Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CBmc Patrol Agent
APPBmc3.23.2.33.2.53.2.73.3.003.4.003.4.11≤ 3.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References
Related vulnerabilities
CVE-2023-34257CRITICAL9.8PL ✓same product
BMC Patrol Agent — zdalne wykonanie kodu przez niezabezpieczoną konfigurację SNMP
CVE-2019-8352CRITICAL9.8PL ✓same product
BMC PATROL Agent — statyczny klucz szyfrowania umożliwia kradzież poświadczeń
CVE-2020-35593HIGH7.8same product
BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -ho...
CVE-2019-17043HIGH7.8same product
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID b...
CVE-2019-17044HIGH7.8same product
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary...