CVE-2023-34258 Information
Jun 02, 2023
cve
Description
An issue was discovered in BMC Patrol before 22.1.00. The agent’s configuration can be remotely queried. This configuration contains the Patrol account password encrypted with a default AES key. This account can then be used to achieve remote code execution.
Reference
https://www.errno.fr/PatrolAdvisory.html#remote-secrets-leak-using-patrols-pconfig-22100 https://gist.github.com/gquere/045638b9959f4b3e119ea01d8d6ff856
Share on: