CVE-2016-1543

HIGH

BMC BladeLogic Server Automation <8.8 - Auth Bypass

Title source: llm

Description

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/43939
exploitdb WORKING POC
by Paul Taylor · pythonremotemultiple
https://www.exploit-db.com/exploits/43902

Scores

CVSS v3 7.5
EPSS 0.7303
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-284
Status published
Products (11)
bmc/bladelogic_server_automation_console 8.2.02
bmc/bladelogic_server_automation_console 8.2.03
bmc/bladelogic_server_automation_console 8.2.04
bmc/bladelogic_server_automation_console 8.3.00
bmc/bladelogic_server_automation_console 8.3.01
bmc/bladelogic_server_automation_console 8.3.02
bmc/bladelogic_server_automation_console 8.3.03
bmc/bladelogic_server_automation_console 8.5.00
bmc/bladelogic_server_automation_console 8.5.01
bmc/bladelogic_server_automation_console 8.6.00
... and 1 more
Published Jun 13, 2016
Tracked Since Feb 18, 2026