CVE-2025-55118
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n"; * Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n"
Scoring
- Severity
- HIGH
- CVSS base score
- 8.9
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L
- EPSS probability
- 0.37%
- CWE
- CWE-122, CWE-125, CWE-787, CWE-191, CWE-665, CWE-835, CWE-415, CWE-416
- Published
- 2025-09-16
- Last modified
- 2026-03-12
Affected products
- BMC Control-M/Agent
- BMC Control-M/Agent
- BMC Control-M/Agent
- BMC Control-M/Agent
- BMC Control-M/Agent
Weakness type
Related vulnerabilities
- CVE-2026-45761 — Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule load
- CVE-2026-42807 — A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec...
- CVE-2026-85103 — Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
- CVE-2026-87430 — Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87579 — Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87654 — Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87527 — Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-53938 — OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)