Skip to content
COOEY

EXPOSURES › CVE-2024-51567

CVE-2024-51567

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-51567 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 95/100 ransomwarerceexploited-in-wildunpatcheddefault-creds

CyberPanel's incorrect default permissions allowed unauthenticated remote attackers to execute commands as root, leading to active exploitation and ransomware incidents.

CyberPanel shipped with incorrect default file permissions, enabling remote, unauthenticated attackers to gain root access and execute arbitrary commands. This is a critical failure for DIB organizations because it represents a severe, avoidable exposure that directly enables ransomware and data breaches, violating CMMC/NIST 800-171 requirements for secure configuration and patch management. Organizations must verify default configurations and apply patches immediately to prevent similar compromises.

Shame score — The vendor shipped with a critical, unpatched vulnerability that was actively exploited in the wild for ransomware, demonstrating severe negligence and a complete failure to secure default configurations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.