Unauthorized Password Reset Vulnerability in BMC BladeLogic Server Automation
CVE-2016-1543

7.5HIGH

Key Information:

Vendor

Bmc

Vendor
CVE Published:
13 June 2016

What is CVE-2016-1543?

The RPC API in the RSCD agent of BMC BladeLogic Server Automation versions 8.2.x through 8.7.x on Linux and UNIX platforms is susceptible to an issue where remote attackers can exploit authorization bypass vulnerabilities. By sending specially crafted action packets to the XML-RPC interface after an authorization failure, attackers may reset arbitrary user passwords, thereby compromising system integrity and security. It is crucial for users of affected versions to implement mitigations and apply patches promptly to safeguard their environments.

References

EPSS Score

73% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.