CVE-1999-0801: Critical severity BMC PATROL Agent vulnerability
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
BMC Patrol Perform Agentfrom your environment.If the agent is not required, uninstall or disable the BMC Patrol Perform Agent until a vendor fix is available.
- Compensating control
Restrict network access to the BMC Patrol Perform Agent: apply firewall/ACL rules to limit connectivity to only trusted management hosts, place the agent on an isolated management VLAN/subnet, and block or filter traffic sources that could be used to deliver spoofed frames.
- Operational
Monitor the agent for signs of unauthorized access (review logs and alerts for suspicious frames or connections) and follow incident-response procedures if compromise is suspected (for example, contain the host, rebuild or reinstall the agent, and rotate any credentials that may have been exposed).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0801?
CVE-1999-0801 is considered a critical vulnerability as it allows remote attackers to gain unauthorized access to BMC Patrol agents.
How do I fix CVE-1999-0801?
To fix CVE-1999-0801, it is recommended to upgrade to a newer version of BMC Patrol agent that addresses this vulnerability.
What software is affected by CVE-1999-0801?
CVE-1999-0801 specifically affects BMC Patrol agent version 3.2.3.
Can CVE-1999-0801 be exploited from outside the network?
Yes, CVE-1999-0801 can be exploited by remote attackers over the network by spoofing frames.
What are the potential consequences of exploiting CVE-1999-0801?
Exploiting CVE-1999-0801 can lead to unauthorized access and control over the BMC Patrol agent, potentially compromising the system's integrity and security.