Loading HuntDB...

GHSA-w8vq-fjr4-4h8v

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges on the network.

Related CVEs

Key Information

GHSA ID
GHSA-w8vq-fjr4-4h8v
Published
May 24, 2022 4:46 PM
Last Modified
April 4, 2024 12:42 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.