Authentication Bypass in BMC Server Automation Leading to Command Execution
CVE-2017-9453

9CRITICAL

Key Information:

Vendor

Bmc

Vendor
CVE Published:
5 September 2023

What is CVE-2017-9453?

A vulnerability exists in BMC Server Automation that allows an attacker to bypass authentication mechanisms. This flaw enables unauthorized users to execute commands via the Process Spawner, potentially compromising the security and integrity of the affected systems. It is crucial for users to apply the necessary patches to mitigate this risk.

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.