Vulnerability record · CVE-2016-1543 · published 13 June 2016
CVE-2016-1543: BMC BladeLogic RSCD agent RPC authorization bypass allows password reset
Bmc · Bladelogic Server Automation Console
The RPC API in the BMC BladeLogic Server Automation RSCD agent fails to enforce authorization, letting a remote attacker send an action packet to xmlrpc after an authorization failure and reset arbitrary user passwords. Because the agent is reachable over the network and no credentials are required, this is a serious integrity flaw for managed Linux and UNIX hosts.
Description
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityUnauthenticated remote integrity impact with public exploit code and very high EPSS, though no KEV listing and no confirmed in-the-wild reports in this record.
What it is
The RPC API in the BMC BladeLogic Server Automation RSCD agent fails to enforce authorization, letting a remote attacker send an action packet to xmlrpc after an authorization failure and reset arbitrary user passwords. Because the agent is reachable over the network and no credentials are required, this is a serious integrity flaw for managed Linux and UNIX hosts.
Impact
An unauthenticated attacker can reset passwords for arbitrary users, potentially taking over accounts and gaining control of systems managed by the RSCD agent.
Attack surface
Reachable remotely over the network via the RSCD agent's xmlrpc interface; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.71854, 99.4th percentile) and public exploit code exists on Exploit-DB, indicating active interest and likely exploitation.
What to do
- Apply the vendor patch referenced in the BMC advisory (selfservice.bmc.com knowledge article).
- Restrict network access to the RSCD agent's RPC/xmlrpc port to trusted management hosts only.
- Upgrade or migrate off the affected 8.2.x through 8.7.x BSA releases.
- Audit and rotate credentials for accounts on managed Linux/UNIX hosts that could have been reset.
- Monitor RSCD agent logs for authorization failures followed by successful xmlrpc actions.
Detection
- Alert on RSCD agent log entries showing an authorization failure immediately followed by a successful xmlrpc action packet.
- Monitor for unexpected password reset events on Linux/UNIX hosts managed by BSA.
- Detect anomalous inbound connections to the RSCD agent RPC port from non-management hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-1543 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-1543), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.