Description
An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38339 | An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution. |
References
History
Wed, 08 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-08T21:11:19.507Z
Reserved: 2023-05-31T00:00:00.000Z
Link: CVE-2023-34258
Updated: 2024-08-02T16:01:54.285Z
Status : Modified
Published: 2023-05-31T20:15:10.903
Modified: 2025-01-08T22:15:28.060
Link: CVE-2023-34258
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD