← Vulnerability feed

Vulnerability record · CVE-2016-1543 · published 13 June 2016

CVE-2016-1543: BMC BladeLogic RSCD agent RPC authorization bypass allows password reset

Bmc · Bladelogic Server Automation Console

The RPC API in the BMC BladeLogic Server Automation RSCD agent fails to enforce authorization, letting a remote attacker send an action packet to xmlrpc after an authorization failure and reset arbitrary user passwords. Because the agent is reachable over the network and no credentials are required, this is a serious integrity flaw for managed Linux and UNIX hosts.

7.5 CVSS 3.0 High EPSS 72% · top 0.6% CWE-284 · Improper access control
7.5CVSS 3.0 base score, v2 5.0
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote integrity impact with public exploit code and very high EPSS, though no KEV listing and no confirmed in-the-wild reports in this record.

What it is

The RPC API in the BMC BladeLogic Server Automation RSCD agent fails to enforce authorization, letting a remote attacker send an action packet to xmlrpc after an authorization failure and reset arbitrary user passwords. Because the agent is reachable over the network and no credentials are required, this is a serious integrity flaw for managed Linux and UNIX hosts.

Impact

An unauthenticated attacker can reset passwords for arbitrary users, potentially taking over accounts and gaining control of systems managed by the RSCD agent.

Attack surface

Reachable remotely over the network via the RSCD agent's xmlrpc interface; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.71854, 99.4th percentile) and public exploit code exists on Exploit-DB, indicating active interest and likely exploitation.

What to do

  • Apply the vendor patch referenced in the BMC advisory (selfservice.bmc.com knowledge article).
  • Restrict network access to the RSCD agent's RPC/xmlrpc port to trusted management hosts only.
  • Upgrade or migrate off the affected 8.2.x through 8.7.x BSA releases.
  • Audit and rotate credentials for accounts on managed Linux/UNIX hosts that could have been reset.
  • Monitor RSCD agent logs for authorization failures followed by successful xmlrpc actions.

Detection

  • Alert on RSCD agent log entries showing an authorization failure immediately followed by a successful xmlrpc action packet.
  • Monitor for unexpected password reset events on Linux/UNIX hosts managed by BSA.
  • Detect anomalous inbound connections to the RSCD agent RPC port from non-management hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-1543 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4322Bmc bladelogic server automation console improper authentication vulnerabilityBMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or p…EPSS 5.2%7.5CVE-2016-1542BMC BladeLogic RSCD agent authorization bypass enables user enumerationThe RPC API in the BMC BladeLogic Server Automation (BSA) RSCD agent on Linux and UNIX fails to enforce authorization correctly, allowing an unauthen…EPSS 75%analysed7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed10.0CVE-2026-48907JCE editor for Joomla allows unauthenticated profile creation and PHP uploadThe JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. Thi…KEVEPSS 16%analysed9.8CVE-2026-35616FortiClientEMS improper access control allows unauthenticated code executionFortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted req…KEVEPSS 9.1%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2016-1543), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.