CVE-2025-55112

7.4

BMC · Control-M/Agent

BMC Control-M/Agent versions 9.0.18 through 9.0.20 contain a hardcoded cryptographic key when using the Blowfish algorithm, allowing attackers to decrypt sensitive network traffic.

Executive summary

A hardcoded cryptographic key vulnerability in legacy BMC Control-M/Agent versions exposes network traffic to potential interception and decryption by unauthorized actors.

Vulnerability

This vulnerability involves the use of a hardcoded cryptographic key within the Blowfish implementation, which is a legacy configuration. An attacker capable of intercepting network traffic between the Agent and the Server can leverage this flaw to decrypt sensitive communications.

Business impact

The compromise of encrypted traffic between the Control-M/Agent and Server can lead to the exposure of sensitive operational data, credentials, or system configurations. Given the CVSS score of 7.4, this vulnerability represents a high risk to data confidentiality and integrity, potentially facilitating further attacks or unauthorized access to the broader automation environment.

Remediation

Immediate Action: Upgrade all instances of BMC Control-M/Agent to version 9.0.21 or later, as these versions are unaffected by this cryptographic flaw.

Proactive Monitoring: Review network traffic logs for unusual patterns or attempts to intercept communication between Control-M infrastructure components.

Compensating Controls: If an immediate upgrade is not feasible, restrict network access to the Agent ports to authorized management segments only and ensure that non-default, insecure cryptographic algorithms are disabled where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The reliance on hardcoded cryptographic keys poses a significant security risk that cannot be mitigated through configuration alone. Organizations should prioritize the transition to version 9.0.21 to ensure modern, secure encryption standards are enforced and to eliminate the possibility of traffic decryption by unauthorized parties.

More BMC CVEs

Sources

Originally found and disclosed by Airbus SAS - Jean-Romain Garnier - seclab@airbus.com, per the CVE Program record.