Aller au contenu

Fiche vulnérabilité

CVE-2023-34257 : faille critique bmc patrol agent (CVSS 9.8)

Description

An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when the agent is restarted. NOTE: the vendor's perspective is "These are not vulnerabilities for us as we have provided the option to implement the authentication."

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
31 mai 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • bmc patrol agent

Références

Rechercher une autre vulnérabilité dans la base CVE