9.5
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration).
NOTE: The vendor believes that this vulnerability only occurs when documented security best practices are not followed. BMC has always strongly recommended to use security best practices such as configuring SSL/TLS between Control-M Server and Agent.
NOTE: The vendor believes that this vulnerability only occurs when documented security best practices are not followed. BMC has always strongly recommended to use security best practices such as configuring SSL/TLS between Control-M Server and Agent.
AI Analysis
Unauthenticated remote code execution, arbitrary file read and write due to default configuration not enforcing SSL/TLS
Basic Information
ID
CVE-2025-55108
Source
airbus
Published
Nov 5, 2025 at 09:07
Modified
Nov 5, 2025 at 14:07
Affected Product
Vendor
BMC
Product
Control-M/Agent
Version
9.0.22
Affected Versions
BMC Control-M/Agent 9.0.22
BMC Control-M/Agent 9.0.21
BMC Control-M/Agent 9.0.20
BMC Control-M/Agent 9.0.19
BMC Control-M/Agent 9.0.18
BMC Control-M/Agent 9.0.21
BMC Control-M/Agent 9.0.20
BMC Control-M/Agent 9.0.19
BMC Control-M/Agent 9.0.18
CWE Classification
AI Assessment
AI Score
9.5 / 10
AI Severity
Critical
Vendor
BMC
Product
Control-M/Agent
Version
9.0.22, 9.0.21, 9.0.20, 9.0.19, 9.0.18