Description
The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported versions
Published: 2026-07-01
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from weak protection of stored password hashes in Control‑M/Enterprise Manager, allowing an attacker who obtains credential data to attempt offline password recovery. This flaw is classified as CWE-328 and carries a CVSS score of 5.6, indicating moderate severity. The potential impact is that compromised credentials could permit unauthorized access to the system or cascading attacks if those credentials are reused elsewhere.

Affected Systems

BMC Control‑M/Enterprise Manager, specifically unsupported releases 9.0.20.x and potentially earlier unsupported versions. No supported versions are listed as affected.

Risk and Exploitability

The lack of an EPSS score and absence from CISA’s KEV catalog suggest a lower likelihood of widespread exploitation at this time, but the risk remains active for organizations still running the unsupported versions. An attacker would need to acquire the credential database or backups to carry out offline brute‑force attempts, a process that can be executed without network interaction. Once a hash is compromised, the attacker can recover the plaintext password using common password cracking tools, leading to system compromise if the credentials grant administrative or privileged access.

Generated by OpenCVE AI on July 1, 2026 at 15:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a supported Control‑M/Enterprise Manager version or apply the vendor-supplied security patch provided in the BMC advisory link (https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=kA3cx000000GFeDCAW&type=Solution).
  • Reset all system account passwords and regenerate stored password hashes using a stronger hashing algorithm that BMC recommends for newer supported versions.
  • Implement strict password policies, enforce regular password rotation, and restrict physical and logical access to the credential database to mitigate the risk of offline recovery attacks.

Generated by OpenCVE AI on July 1, 2026 at 15:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Bmc
Bmc control-m/enterprise Manager
Vendors & Products Bmc
Bmc control-m/enterprise Manager

Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported versions
Title Weak password hash protection in Control-M/Entreprise Manager
Weaknesses CWE-328
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Bmc Control-m/enterprise Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2026-07-01T12:34:11.299Z

Reserved: 2026-06-01T12:16:12.516Z

Link: CVE-2026-10540

cve-icon Vulnrichment

Updated: 2026-07-01T12:34:03.614Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T15:15:04Z

Weaknesses