CVE-2025-55112: BMC Control-M/Agent hardcoded Blowfish keys
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent and Server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55112?
CVE-2025-55112 has a critical severity due to the potential for attackers to decrypt sensitive network traffic.
How do I fix CVE-2025-55112?
To mitigate CVE-2025-55112, upgrade to a supported version of Control-M/Agent that does not use the hardcoded Blowfish key.
What versions are affected by CVE-2025-55112?
CVE-2025-55112 affects BMC Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.
What risks are associated with CVE-2025-55112?
The risks associated with CVE-2025-55112 include potential unauthorized decryption of sensitive data transmitted over the network.
Is there a workaround for CVE-2025-55112?
There are no specific workarounds for CVE-2025-55112, and upgrading to a secure version is the recommended course of action.