Vulnerability Details CVE-2019-8352
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges on the network.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.054
EPSS Ranking 89.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-8352
-
cpe:2.3:a:bmc:patrol_agent:-
-
cpe:2.3:a:bmc:patrol_agent:10.0.00
-
cpe:2.3:a:bmc:patrol_agent:10.0.00.01
-
cpe:2.3:a:bmc:patrol_agent:10.0.00.02
-
cpe:2.3:a:bmc:patrol_agent:10.7.00
-
cpe:2.3:a:bmc:patrol_agent:10.7.00.01
-
cpe:2.3:a:bmc:patrol_agent:10.7.00.02
-
cpe:2.3:a:bmc:patrol_agent:10.7.00.03
-
cpe:2.3:a:bmc:patrol_agent:10.7.00.04
-
cpe:2.3:a:bmc:patrol_agent:10.7.00.05
-
cpe:2.3:a:bmc:patrol_agent:11.0.00
-
cpe:2.3:a:bmc:patrol_agent:11.0.00.01
-
cpe:2.3:a:bmc:patrol_agent:11.0.00.02
-
cpe:2.3:a:bmc:patrol_agent:11.0.00.03
-
cpe:2.3:a:bmc:patrol_agent:11.3.01
-
cpe:2.3:a:bmc:patrol_agent:3.2
-
cpe:2.3:a:bmc:patrol_agent:3.2.3
-
cpe:2.3:a:bmc:patrol_agent:3.2.5
-
cpe:2.3:a:bmc:patrol_agent:3.2.7
-
cpe:2.3:a:bmc:patrol_agent:3.3.00
-
cpe:2.3:a:bmc:patrol_agent:3.4.00
-
cpe:2.3:a:bmc:patrol_agent:3.4.11
-
cpe:2.3:a:bmc:patrol_agent:3.7
-
cpe:2.3:a:bmc:patrol_agent:3.9.00
-
cpe:2.3:a:bmc:patrol_agent:9.0.10i
-
cpe:2.3:a:bmc:patrol_agent:9.5.00
-
cpe:2.3:a:bmc:patrol_agent:9.5.00.01
-
cpe:2.3:a:bmc:patrol_agent:9.5.00.02
-
cpe:2.3:a:bmc:patrol_agent:9.5.00.03
-
cpe:2.3:a:bmc:patrol_agent:9.5.00.04
-
cpe:2.3:a:bmc:patrol_agent:9.5.00.05
-
cpe:2.3:a:bmc:patrol_agent:9.6.00
-
cpe:2.3:a:bmc:patrol_agent:9.6.00.01
-
cpe:2.3:a:bmc:patrol_agent:9.6.00.02
-
cpe:2.3:a:bmc:patrol_agent:9.6.00.03
-
cpe:2.3:a:bmc:patrol_agent:9.6.00.04
-
cpe:2.3:a:bmc:patrol_agent:9.6.00.05