An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when the agent is restarted. NOTE: the vendor's perspective is "These are not vulnerabilities for us as we have provided the option to implement the authentication."
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-05-31T00:00:00
Updated: 2024-08-02T16:01:54.344Z
Reserved: 2023-05-31T00:00:00
Link: CVE-2023-34257
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-31T20:15:10.860
Modified: 2024-11-21T08:06:52.500
Link: CVE-2023-34257
Redhat
No data.