216.73.216.6

CVE-2025-55109

· Published 16/09/2025 13:16 · Modified 17/09/2025 14:18

Labels: CVE-2025-55109 2025-09-16CVE-2025-55109CWE-295[email protected]

Essential information

Published
16/09/2025 13:16
Modified
17/09/2025 14:18
Author
Creator
CVSS
9.5 CRITICAL (v3) 9.5 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed third-party or demo certificate for client authentication can bypass the need for a certificate signed by the certificate authority of the organization during authentication on the Control-M/Agent. The Control-M/Agent contains hardcoded certificates which are only trusted as fallback if an empty kdb keystore is used; they are never trusted if a PKCS#12 keystore is used. All of these certificates are now expired. In addition, the Control-M/Agent default kdb and PKCS#12 keystores contain trusted third-party certificates (external recognized CAs and default self-signed demo certificates) which are trusted for client authentication.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
bmc / control-m cpe:2.3:a:bmc:control-m:9.0.18-9.0.20:*:*:*:*:*:*:*

References