CVE-2025-55118HIGH 8.9EPSS p26.0%
CVE-2025-55118CVE-2025-55118
Description
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured.
The issue occurs in the following cases:
* Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n";
* Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n"
Scoring
| CVSS 3.1 | 8.9 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H |
| EPSS | 0.34% probability of exploitation · percentile 26.0% · 2026-06-18T12:00:27Z |
| Published | 2025-09-16 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 8
References
8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Heap-based Buffer Overflowcwe-122 | 0% | live |
| Weakness | Out-of-bounds Readcwe-125 | 0% | live |
| Weakness | Integer Underflow (Wrap or Wraparound)cwe-191 | 0% | live |
| Weakness | Double Freecwe-415 | 0% | live |
| Weakness | Use After Freecwe-416 | 0% | live |
| Weakness | Improper Initializationcwe-665 | 0% | live |
| Weakness | Out-of-bounds Writecwe-787 | 0% | live |
| Weakness | Loop with Unreachable Exit Condition ('Infinite Loop')cwe-835 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.