Vulnerabilities
73 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-23781 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow unauthorized access to the MFT API debug interface. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2025-71260 | Authenticated ASP.NET VIEWSTATE Deserialization RCE in BMC FootPrints ITSM BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data flaw (CWE-502) in the ASP.NET servlet's handling of the VIEWSTATE parameter. An authenticated attacker with low privileges can submit crafted serialized objects in the VIEWSTATE parameter over the network, with no user interaction required. Successful exploitation yields arbitrary code execution, allowing the attacker to fully compromise the ITSM application and its host (high impact to confidentiality, integrity, and availability). Organizations running any affected FootPrints ITSM release are exposed, particularly where the web interface is reachable from untrusted networks. No confirmed in-the-wild exploitation has been reported and it is not in CISA KEV, but a public PoC exists (WatchTowr Labs research, which also describes pre-authentication RCE chains against FootPrints), and the 34.4% EPSS score (98th percentile) indicates an elevated probability of exploitation within 30 days. Do: Upgrade each deployment to the remediation hotfix matching its baseline release, choosing from the vendor-listed builds (20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01). Until patched, restrict network access to the FootPrints web interface, verify ASP.NET VIEWSTATE integrity (MAC/encryption) settings are enabled, and review web logs for suspicious POST requests to the ASP.NET servlet. | 8.7 group max | 34% | PoC |
| moderateon the order of 1,000-10,000 installations (estimated) | |
| CVE-2021-47718 | OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing fu OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information. NVD description · AI analysis pending | 8.7 group max | <1% | PoC ×2 |
| — | |
| CVE-2025-55109 | An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed third-party or demo certificate for client authentication can bypass the need for a certificate signed by the certificate authority of the organization during authentication on the Control-M/Agent. The Control-M/Agent contains hardcoded certificates which are only trusted as fallback if an empty kdb keystore is used; they are never trusted if a PKCS#12 keystore is used. All of these certificates are now expired. In addition, the Control-M/Agent default kdb and PKCS#12 keystores contain trusted third-party certificates (external recognized CAs and default self-signed demo certificates) which are trusted for client authentication. NVD description · AI analysis pending | 9.5 group max | <1% |
| — | ||
| CVE-2025-48709 | BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a database connection on, it runs 'DBUStatus.exe' frequently, which then calls 'dbu_connection_details.vbs' with the username, password, database hostname, and port written in cleartext, which can be seen in event and process logs in two separate locations. Fixed in PACTV.9.0.21.307. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2024-34398 | An issue was discovered in BMC Remedy Mid Tier 7.6.04. An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers. NVD description · AI analysis pending | 4.2 | <1% |
| — | ||
| CVE-2024-34399 | **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer and the impacted version for this vulnerability is 7.6.04 only. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2021-35002 +1 in the same advisory: …35001 | BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of email attachments. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-14122. NVD description · AI analysis pending | 8.8 group max | 2% |
| — | ||
| CVE-2024-1605 | BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all us BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, which will execute with the application's privileges. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2020-35593 | BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host. BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2017-9453 | BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-39122 | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200). NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-34258 | An issue was discovered in BMC Patrol before 22.1.00. An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution. NVD description · AI analysis pending | 7.5 | <1% | PoC ×2 |
| — | |
| CVE-2023-34257 | An issue was discovered in BMC Patrol through 23.1.00. An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when the agent is restarted. NOTE: the vendor's perspective is "These are not vulnerabilities for us as we have provided the option to implement the authentication." NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-39295 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface. In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2023-26550 | A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field. A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-35729 | Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of service Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of service via network access. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2022-26088 | An issue was discovered in BMC Remedy before 22.1. An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of recipients" field. NOTE: the vendor's position is that "no real impact is demonstrated." NVD description · AI analysis pending | 5.4 | 1% | PoC ×3 |
| — | |
| CVE-2022-3409 +1 in the same advisory: …2809 | A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http headers. If long enough http header is passed in the multipart form without colon there is one byte overwrite on heap. It can be conducted multiple times in a loop to cause DoS. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2022-35865 +1 in the same advisory: …35864 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-16709. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2022-24047 | This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-14618. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-39296 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. NVD description · AI analysis pending | 10.0 | 3% | PoC |
| — | |
| CVE-2017-17674 | BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE). NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2020-14156 | user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions. user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2019-19220 | BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2). BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2). NVD description · AI analysis pending | 8.8 group max | 2% |
| — |