Skip to content
COOEY

EXPOSURES › CVE-2024-51378

CVE-2024-51378

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-51378 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatcheddefault-credsnegligence

CyberPanel's incorrect default permissions allow authentication bypass and arbitrary command execution via shell metacharacters in the statusfile property.

CyberPanel shipped with incorrect default permissions that permit authentication bypass and arbitrary command execution using shell metacharacters in the statusfile property. This is a critical, actively exploited vulnerability linked to ransomware that exposes DIB organizations to data breaches and compliance failures. Organizations must immediately patch CyberPanel and restrict default configurations to prevent exploitation.

Shame score — The vendor shipped with incorrect default permissions that allow authentication bypass and arbitrary command execution, a negligent and avoidable flaw actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.