module
VICIdial Authenticated Remote Code Execution
Disclosed | Created |
---|---|
2024-09-10 | 2024-10-01 |
Disclosed
2024-09-10
Created
2024-10-01
Description
An attacker with authenticated access to VICIdial as an "agent"
can execute arbitrary shell commands as the "root" user. This
attack can be chained with CVE-2024-8503 to execute arbitrary
shell commands starting from an unauthenticated perspective.
can execute arbitrary shell commands as the "root" user. This
attack can be chained with CVE-2024-8503 to execute arbitrary
shell commands starting from an unauthenticated perspective.
Authors
Valentin Lobstein
Jaggar Henry of KoreLogic, Inc.
Jaggar Henry of KoreLogic, Inc.
Platform
Linux,Unix
Architectures
ARCH_CMD
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.