CRITICAL🇵🇱 Wersja polska

CVE-2025-55109

CVSS 9.5v4.0pub. 2025-09-16upd. 2025-10-10

An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed third-party or demo certificate for client authentication can bypass the need for a certificate signed by the certificate authority of the organization during authentication on the Control-M/Agent. The Control-M/Agent contains hardcoded certificates which are only trusted as fallback if an empty kdb keystore is used; they are never trusted if a PKCS#12 keystore is used. All of these certificates are now expired. In addition, the Control-M/Agent default kdb and PKCS#12 keystores contain trusted third-party certificates (external recognized CAs and default self-signed demo certificates) which are trusted for client authentication.

🤖 AI Analysis
How it works

The vulnerability results from improper client certificate validation (CWE-295) during authentication to Control-M/Agent. When an empty or default kdb keystore or default PKCS#12 keystore is used, the agent accepts certificates issued by trusted external CAs or default demonstration certificates as valid for client authentication. Additionally, the agent contains hardcoded certificates that are treated as fallback trusted — only in the case of an empty kdb keystore. All hardcoded certificates are already expired, however the mere presence of external and demonstration certificates in default keystores still enables the attack to be carried out.

Impact

An attacker can authenticate to Control-M/Agent, bypassing organizational certificate control mechanisms, which may lead to unauthorized access to managed tasks and systems, and consequently to complete takeover of the agent and associated resources.

Mitigation & patch

Patches available from the vendor should be applied according to references (BMC Knowledge Articles sfdcid=000441963 and sfdcid=000442099). As remedial measures, replace default and empty keystores (kdb and PKCS#12) with custom keystores containing only certificates issued by organizational CAs, remove all demonstration certificates and external CA certificates from trusted key stores, and consider migration to versions with active vendor support.

Who is affected

BMC Control-M/Agent versions 9.0.18 through 9.0.20 (out-of-support versions) and potentially earlier unsupported versions when configured with an empty or default kdb keystore or default PKCS#12 keystore.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bmc Control M\/agent

    APP
    Bmc
    ≤ 9.0.22
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-55113CRITICAL9.5PL ✓same product

BMC Control-M/Agent: Bypass ACL przez NULL byte w certyfikacie klienta

CVE-2025-55115CRITICAL9.3PL ✓same product

Path traversal w BMC Control-M/Agent prowadzący do privilege escalation

CVE-2025-55116CRITICAL9.3PL ✓same product

Buffer overflow w BMC Control-M/Agent umożliwiający privilege escalation

CVE-2025-55112HIGH7.6same product

Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that a...

CVE-2025-55111MEDIUM5.7same product

Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent version...