Lucene search

K
vulnrichmentKoreLogicVULNRICHMENT:CVE-2024-8504
HistorySep 10, 2024 - 7:23 p.m.

CVE-2024-8504 VICIdial Authenticated Remote Code Execution

2024-09-1019:23:39
CWE-78
KoreLogic
github.com
7
vicidial
authenticated
remote code execution
vulnerability

AI Score

7.6

Confidence

Low

EPSS

0.003

Percentile

65.6%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

An attacker with authenticated access to VICIdial as an “agent” can execute arbitrary shell commands as the “root” user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:vicidial:vicidial:2.14-917a:*:*:*:*:*:*:*"
    ],
    "vendor": "vicidial",
    "product": "vicidial",
    "versions": [
      {
        "status": "affected",
        "version": "2.14-917a"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

7.6

Confidence

Low

EPSS

0.003

Percentile

65.6%

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total