CVE-2023-34258: High severity BMC Patrol vulnerability
An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BMC Patrolto a version that resolves this vulnerability.Fixed in 22.1.00
Event History
Frequently Asked Questions
What is CVE-2023-34258?
CVE-2023-34258 is a vulnerability discovered in BMC Patrol before version 22.1.00. It allows remote querying of the agent's configuration, leading to the exposure of the Patrol account password that is encrypted with a default AES key.
How severe is CVE-2023-34258?
CVE-2023-34258 has a severity level of 7.5, which is considered high.
What is the affected software for CVE-2023-34258?
The affected software for CVE-2023-34258 is BMC Patrol version up to exclusive 22.1.00.
How can the vulnerability in CVE-2023-34258 be exploited?
The vulnerability in CVE-2023-34258 can be exploited by remotely querying the agent's configuration to obtain the encrypted Patrol account password, which can then be used for remote code execution.
Is there a fix available for CVE-2023-34258?
Yes, updating to BMC Patrol version 22.1.00 or later will fix the vulnerability in CVE-2023-34258.