As cited
Copy frozen at (site build).
vulnerabilities
The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)
watchTowr Labs discovered four chained vulnerabilities in BMC FootPrints ITSM solution, including authentication bypass, server-side request forgery, and deserialization flaws that enable pre-authenticated remote code execution. The vulnerabilities affect BMC FootPrints versions 20.20.02 through 20.24.01.001, and disclosure to BMC began in June 2025. ITSM solutions like FootPrints are high-value targets because they manage IT inventory, configuration data, and incident information that organized threat actors leverage for ransomware campaigns.
Why it matters: Organizations running BMC FootPrints should immediately assess their deployment versions and apply patches when available, as ITSM solutions are frequently targeted by ransomware operators for lateral movement and reconnaissance due to their access to sensitive infrastructure data.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)
watchTowr Labs discovered four chained vulnerabilities in BMC FootPrints ITSM solution, including authentication bypass, server-side request forgery, and deserialization flaws that enable pre-authenticated remote code execution. The vulnerabilities affect BMC FootPrints versions 20.20.02 through 20.24.01.001, and disclosure to BMC began in June 2025. ITSM solutions like FootPrints are high-value targets because they manage IT inventory, configuration data, and incident information that organized threat actors leverage for ransomware campaigns.
Why it matters: Organizations running BMC FootPrints should immediately assess their deployment versions and apply patches when available, as ITSM solutions are frequently targeted by ransomware operators for lateral movement and reconnaissance due to their access to sensitive infrastructure data.
- Source published
- First seen by Cybersecurity Tracker