CVE-2025-55108: BMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code execution
The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration).
NOTE:
The vendor believes that this vulnerability only occurs when documented security best practices are not followed. BMC has always strongly recommended to use security best practices such as configuring SSL/TLS between Control-M Server and Agent.
The vendor notifies that Control-M/Agent is not impacted in Control-M SaaS
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55108?
CVE-2025-55108 is classified as a high-severity vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2025-55108?
To mitigate CVE-2025-55108, enable mutual SSL/TLS authentication in the configuration of BMC Control-M/Agent.
What actions can be exploited in CVE-2025-55108?
CVE-2025-55108 allows attackers to perform unauthenticated remote code execution and unauthorized file read and write operations.
Which software is affected by CVE-2025-55108?
The vulnerability CVE-2025-55108 affects BMC Control-M/Agent when mutual SSL/TLS authentication is not enabled.
Is CVE-2025-55108 present in default configurations?
Yes, CVE-2025-55108 exists in default configurations of BMC Control-M/Agent where mutual SSL/TLS authentication is not activated.