VICIdial Authenticated Remote Code Execution
58Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 8.8epss 76%
da publicação à arma0 dias
Publicada no NVD10 de set.
metasploit10 de set.
probabilidade de exploração
76%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
VICIdial · VICIdial