CVE-2025-55110: BMC Control-M/Agent hardcoded default keystore password
Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documented.
An attacker with read access to the keystore could access sensitive data using this password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55110?
CVE-2025-55110 is considered a high-severity vulnerability due to the exposure of sensitive data through default keystore passwords.
How do I fix CVE-2025-55110?
To mitigate CVE-2025-55110, change the default keystore password to a strong, unique password.
Who is affected by CVE-2025-55110?
CVE-2025-55110 affects users of BMC Control-M/Agent that utilize the default keystore configuration.
What could an attacker do with CVE-2025-55110?
An attacker with read access to the keystore could exploit CVE-2025-55110 to access sensitive data stored within it.
Is CVE-2025-55110 easily exploitable?
Yes, CVE-2025-55110 can be easily exploited if an attacker gains read access to the keystore due to the known default password.