Critical severity9.8NVD Advisory· Published Oct 17, 2019· Updated Jun 17, 2026
CVE-2019-13657
CVE-2019-13657
Description
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.
Affected products
6cpe:2.3:a:broadcom:ca_performance_management:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:broadcom:ca_performance_management:*:*:*:*:*:*:*:*range: >=3.6.0,<3.6.9
- cpe:2.3:a:broadcom:ca_performance_management:3.5.0:*:*:*:*:*:*:*
- (no CPE)range: 3.5.x, 3.6.x < 3.6.9, 3.7.x < 3.7.4
- cpe:2.3:a:broadcom:network_operations:*:*:*:*:*:*:*:*Range: <=19.1
- Range: 3.5.x, 3.6.x < 3.6.9, 3.7.x < 3.7.4
- CA Technologies, A Broadcom Company/CA Performance Managementv5Range: 3.5.x
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/154904/CA-Performance-Management-Arbitary-Command-Execution.htmlnvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/154904/CA-Performance-Management-Arbitrary-Command-Execution.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/Oct/37nvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2019/Oct/26nvdIssue TrackingMailing ListThird Party Advisory
- techdocs.broadcom.com/us/product-content/recommended-reading/security-notices/ca-20191015-01-security-notice-for-ca-performance-management.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.