Remote Code Execution Vulnerability in BMC Patrol Agent Configuration
CVE-2023-34258

7.5HIGH

Key Information:

Vendor

Bmc

Status
Vendor
CVE Published:
31 May 2023

What is CVE-2023-34258?

A vulnerability has been identified in BMC Patrol versions prior to 22.1.00, where the agent's configuration can be remotely accessed. This configuration may inadvertently expose the Patrol account password, which is encrypted using a default AES key. Attackers can leverage this information to potentially execute code remotely, creating significant risks for affected systems. Organizations utilizing BMC Patrol should take immediate steps to secure their configurations and update to the latest version to mitigate this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.