SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-1543

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc…

HIGH 7.5EPSS 71.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 71.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
71.85% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
bmc/bladelogic server automation console
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.