CVE-2014-4872 is a critical authentication bypass vulnerability affecting BMC Track-It! 11.3.0.355. It allows unauthenticated remote attackers to upload arbitrary files, execute arbitrary code, or steal sensitive credentials and configuration data via .NET Remoting requests to specific services on TCP port 9010. With a CVSS score of 7.5 and a FAUCET Risk Score of 99/100, this vulnerability presents a high risk due to its network-based attack vector and lack of authentication, leading to potential complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, exploit modules are publicly available in Metasploit and ExploitDB, and it has garnered significant community discussion and media coverage, indicating a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3.0.355CPE matchmatch criteria | cpe:2.3:a:bmc:track-it\!:11.3.0.355:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.