Описание
An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 22.1.00 (исключая)
cpe:2.3:a:bmc:patrol:*:*:*:*:*:*:*:*
EPSS
Процентиль: 41%
0.00189
Низкий
7.5 High
CVSS3
Дефекты
CWE-311
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution.
EPSS
Процентиль: 41%
0.00189
Низкий
7.5 High
CVSS3
Дефекты
CWE-311