← volver
CVE-2024-8504highCWE-78

VICIdial Authenticated Remote Code Execution

58Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 8.8epss 76%
de la publicación al arma0 días
Publicada en NVD10 sept
metasploit10 sept
probabilidad de explotación
76%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
VICIdial · VICIdial