Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent and Server.
History

Fri, 10 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Bmc control-m\/agent
CPEs cpe:2.3:a:bmc:control-m\/agent:*:*:*:*:*:*:*:*
Vendors & Products Bmc control-m\/agent

Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Bmc
Bmc control-m/agent
Vendors & Products Bmc
Bmc control-m/agent

Tue, 16 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
Description Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent and Server.
Title BMC Control-M/Agent hardcoded Blowfish keys
Weaknesses CWE-321
CWE-327
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published: 2025-09-16T12:19:24.308Z

Updated: 2025-09-17T03:55:54.628Z

Reserved: 2025-08-07T07:23:59.125Z

Link: CVE-2025-55112

cve-icon Vulnrichment

Updated: 2025-09-16T18:22:34.367Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-16T13:16:06.270

Modified: 2025-10-10T14:01:21.850

Link: CVE-2025-55112

cve-icon Redhat

No data.