CVE-2025-55110

MEDIUM

Control-M/Agents - Info Disclosure

Title source: llm
STIX 2.1

Description

Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documented. An attacker with read access to the keystore could access sensitive data using this password.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 4.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1392
Status published
Products (5)
BMC/Control-M/Agent 9.0.18
BMC/Control-M/Agent 9.0.19
BMC/Control-M/Agent 9.0.20
BMC/Control-M/Agent 9.0.21
BMC/Control-M/Agent 9.0.22
Published Sep 16, 2025
Tracked Since Feb 18, 2026