CVE-2023-34258: Bmc Patrol

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a default AES key. This account can then be used to achieve remote code execution.

Affected products

  • Bmc Patrol: before 22.1.00 (fixed in 22.1.00)

Published 2023-05-31. Last modified 2026-06-17.