Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CBmc Patrol Agent
APPBmc3.23.2.33.2.53.2.73.3.003.4.003.4.11≤ 3.7
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Referencje
Powiązane podatności
CVE-2023-34257CRITICAL9.8PL ✓ten sam produkt
BMC Patrol Agent — zdalne wykonanie kodu przez niezabezpieczoną konfigurację SNMP
CVE-2019-8352CRITICAL9.8PL ✓ten sam produkt
BMC PATROL Agent — statyczny klucz szyfrowania umożliwia kradzież poświadczeń
CVE-2020-35593HIGH7.8ten sam produkt
BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -ho...
CVE-2019-17043HIGH7.8ten sam produkt
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID b...
CVE-2019-17044HIGH7.8ten sam produkt
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary...