CVE-2024-6127
🟠 Łataj w tym tygodniu
Wykorzystanie przejścia ścieżki w BC Security Empire umożliwia zdalne wykonanie kodu.
CVSS
9.8
EPSS
10.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.
path-traversal rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 10.3% |
| Opublikowano (NVD) | 2024-06-27 20:15:23 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-14 23:17:18 UTC |
Referencje
- https://aceresponder.com/blog/exploiting-empire-c2-framework (disclosure@vulncheck.com)
- https://github.com/ACE-Responder/Empire-C2-RCE-PoC (disclosure@vulncheck.com)
- https://github.com/BC-SECURITY/Empire/blob/8283bbc77250232eb493bf1f9104fdd0d468962a/CHANGELOG.md?plain=1#L102 (disclosure@vulncheck.com)
- https://vulncheck.com/advisories/empire-unauth-rce (disclosure@vulncheck.com)