# CVE-2025-55118

## Summary

- **CVE ID:** CVE-2025-55118
- **Severity:** HIGH
- **CVSS Score:** 8.9 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L)
- **CWE:** CWE-122, CWE-125, CWE-787, CWE-191, CWE-665, CWE-835, CWE-415, CWE-416
- **Published:** Sep 16, 2025
- **Last Modified:** Mar 12, 2026

## Description

Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured.


The issue occurs in the following cases:

  *  Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n";
  *  Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n"

## Affected Products

- BMC — Control-M/Agent (9.0.22.000)
- BMC — Control-M/Agent (9.0.21)
- BMC — Control-M/Agent (9.0.20)
- BMC — Control-M/Agent (9.0.19)
- BMC — Control-M/Agent (9.0.18)

## References

- [CNA](https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000442099)
- [CNA](https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000441972)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.37%
- **EPSS Percentile:** 30.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._