CVE-2025-55112
7.4BMC · Control-M/Agent
BMC Control-M/Agent versions 9.0.18 through 9.0.20 contain a hardcoded cryptographic key when using the Blowfish algorithm, allowing attackers to decrypt sensitive network traffic.
Executive summary
A hardcoded cryptographic key vulnerability in legacy BMC Control-M/Agent versions exposes network traffic to potential interception and decryption by unauthorized actors.
Vulnerability
This vulnerability involves the use of a hardcoded cryptographic key within the Blowfish implementation, which is a legacy configuration. An attacker capable of intercepting network traffic between the Agent and the Server can leverage this flaw to decrypt sensitive communications.
Business impact
The compromise of encrypted traffic between the Control-M/Agent and Server can lead to the exposure of sensitive operational data, credentials, or system configurations. Given the CVSS score of 7.4, this vulnerability represents a high risk to data confidentiality and integrity, potentially facilitating further attacks or unauthorized access to the broader automation environment.
Remediation
Immediate Action: Upgrade all instances of BMC Control-M/Agent to version 9.0.21 or later, as these versions are unaffected by this cryptographic flaw.
Proactive Monitoring: Review network traffic logs for unusual patterns or attempts to intercept communication between Control-M infrastructure components.
Compensating Controls: If an immediate upgrade is not feasible, restrict network access to the Agent ports to authorized management segments only and ensure that non-default, insecure cryptographic algorithms are disabled where possible.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The reliance on hardcoded cryptographic keys poses a significant security risk that cannot be mitigated through configuration alone. Organizations should prioritize the transition to version 9.0.21 to ensure modern, secure encryption standards are enforced and to eliminate the possibility of traffic decryption by unauthorized parties.
More BMC CVEs
Sources
Originally found and disclosed by Airbus SAS - Jean-Romain Garnier - seclab@airbus.com, per the CVE Program record.