CVE-2025-55108 is a critical unauthenticated remote code execution vulnerability affecting BMC Control-M/Agent versions 9.0.18 through 9.0.22 when mutual SSL/TLS authentication is not enabled, which is the default configuration. This flaw, rated 10.0 CVSS, allows attackers to achieve full compromise including arbitrary file read/write and other unauthorized actions. While the vendor states it only occurs when security best practices are not followed, there is no public exploit code available, and it is not currently known to be actively exploited, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| BMC | Control-M/Agent | 9.0.18, 9.0.19, 9.0.20, 9.0.21, 9.0.22CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.