Vulnerability Description
The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent to vulnerabilities in the SSL/TLS implementation under certain non-default conditions (e.g. CVE-2025-55117 or CVE-2025-55118) or potentially to resource exhaustion.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000441968
- https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000442099
FAQ
What is CVE-2025-55114?
CVE-2025-55114 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent...
How severe is CVE-2025-55114?
CVE-2025-55114 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55114?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.