bmcapps.my.site.commitigation
https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000441968 CVE-2025-55114
MEDIUM
BMC Control-M/Agent improper IP address filtering order
Record summary
CVE-2025-55114 has a selected CVSS score of 6.9 (medium).
Description
The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent to vulnerabilities in the SSL/TLS implementation under certain non-default conditions (e.g. CVE-2025-55117 or CVE-2025-55118) or potentially to resource exhaustion.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Control-M/AgentBrowse BMC / Control-M/AgentDefault status: affected | CVE List | 9.0.21 | unaffected |
| 9.0.20 | affected | ||
| 9.0.19 | affected | ||
| 9.0.18 | affected |
References
3bmcapps.my.site.comVendor advisory
https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000442099 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-55114