← back
CVE-2024-8504highCWE-78

VICIdial Authenticated Remote Code Execution

58Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.8epss 76%
from disclosure to weapon0 days
Published on NVDSep 10
metasploitSep 10
exploitation probability
76%top 1% of all CVEs
observed exploitation
nono source reports it
An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
VICIdial · VICIdial