BMC.Patrol.Agent.Privilege.Escalation.Remote.Command.Execution

description-logoDescription

This indicates an attack attempt to exploit an Remote Command Execution vulnerability in BMC Patrol Agent.
The vulnerability is due to an design error when the vulnerable software handles a command request from an authenticated user without root or admin privilege. A remote authenticate attacker may be able to exploit this to execute command within the context of the root user.

affected-products-logoAffected Products

BMC Patrol Agent version 11.3.01 and prior

Impact logoImpact

Privilege Escalation: Remote attackers can leverage their privileges on vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are unaware of any vendor supplied patch or updates available for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-10-25 14.711 Default_action:pass:drop
2019-06-06 14.627

References

46556