Control-M/Agent 9.0.18-9.0.20 ACL Bypass via NULL byte in cert
CVE-2025-55113 Published on September 16, 2025
BMC Control-M/Agent unescaped NULL byte in access control list checks
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL byte encountered in the email address referenced in the client certificate. An attacker could bypass configured ACLs by using a specially crafted certificate.
Vulnerability Analysis
CVE-2025-55113 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Improper Neutralization of Null Byte or NUL Character
The software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component. As data is parsed, an injected NUL character or null byte may cause the software to believe the input is terminated earlier than it actually is, or otherwise cause the input to be misinterpreted. This could then be used to inject potentially dangerous input that occurs after the null byte or otherwise bypass validation routines and other protection mechanisms.
Products Associated with CVE-2025-55113
Want to know whenever a new CVE is published for Bmc Control M? stack.watch will email you.
Affected Versions
BMC Control-M/Agent:- Version 9.0.22.000 is affected.
- Version 9.0.21 is affected.
- Version 9.0.20 is affected.
- Version 9.0.19 is affected.
- Version 9.0.18 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.