CVE-2025-55112

HIGH

Control-M/Agent <9.0.20 - Info Disclosure

Title source: llm
STIX 2.1

Description

Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent and Server.

Scores

CVSS v3 7.4
EPSS 0.0002
EPSS Percentile 4.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-327 CWE-321
Status published
Products (1)
bmc/control-m\/agent < 9.0.20.200
Published Sep 16, 2025
Tracked Since Feb 18, 2026