Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore and policies. An attacker with local access to the system running the Agent can access these files.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-29572 Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore and policies. An attacker with local access to the system running the Agent can access these files.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 29 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Bmc control-m\/agent
Linux
Linux linux Kernel
CPEs cpe:2.3:a:bmc:control-m\/agent:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Bmc control-m\/agent
Linux
Linux linux Kernel

Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Bmc
Bmc control-m/agent
Vendors & Products Bmc
Bmc control-m/agent

Tue, 16 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
Description Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore and policies. An attacker with local access to the system running the Agent can access these files.
Title BMC Control-M/Agent insecure default file permissions
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2025-09-16T18:29:31.739Z

Reserved: 2025-08-07T07:23:59.125Z

Link: CVE-2025-55111

cve-icon Vulnrichment

Updated: 2025-09-16T18:26:18.126Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-16T13:16:05.643

Modified: 2025-09-29T12:08:29.103

Link: CVE-2025-55111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-17T10:04:52Z