CVE 9.5 CRITICAL

BMC Control-M/Agent unescaped NULL byte in access control list checks_CVE-2025-55113

9.5 / 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL byte encountered in the email address referenced in the client certificate. An attacker could bypass configured ACLs by using a specially crafted certificate.

Basic Information

ID CVE-2025-55113
Source airbus
Published Sep 16, 2025 at 12:20

Affected Product

Vendor BMC
Product Control-M/Agent
Version 9.0.22.000
Affected Versions BMC Control-M/Agent 9.0.22.000
BMC Control-M/Agent 9.0.21
BMC Control-M/Agent 9.0.20
BMC Control-M/Agent 9.0.19
BMC Control-M/Agent 9.0.18

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.