CVE-2007-1972

N/A Unknown
Published: April 22, 2007 Modified: April 23, 2026
View on NVD

Description

PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://securityreason.com/securityalert/2599
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/466223/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/466274/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/23559
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1017935
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1458
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.zerodayinitiative.com/advisories/ZDI-07-020.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
6.6%
91th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

bmc