VulnerabilityModified
CVE-2007-2136
Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed.
HIGH 7.5EPSS 4.34%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.34% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- bmc/patrol perform agent
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24937
- http://securityreason.com/securityalert/2598
- http://www.securityfocus.com/archive/1/466222/100/0/threaded
- http://www.securityfocus.com/bid/23557
- http://www.securitytracker.com/id?1017934
- http://www.vupen.com/english/advisories/2007/1457
- http://www.zerodayinitiative.com/advisories/ZDI-07-019.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33745
- http://secunia.com/advisories/24937
- http://securityreason.com/securityalert/2598
- http://www.securityfocus.com/archive/1/466222/100/0/threaded
- http://www.securityfocus.com/bid/23557
- http://www.securitytracker.com/id?1017934
- http://www.vupen.com/english/advisories/2007/1457
- http://www.zerodayinitiative.com/advisories/ZDI-07-019.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33745
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.