CVE-2024-5651

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Aug 12, 2024
Updated: Aug 30, 2024
CWE ID 94

Summary

CVE-2024-5651 is a newly discovered vulnerability affecting the Fence Agents Remediation operator. This issue enables a Remote Code Execution (RCE) Primitive by allowing the execution of arbitrary commands through the --ssh-path/--telnet-path arguments. A low-privilege user, such as a developer, can exploit this vulnerability by creating a specially crafted FenceAgentsRemediation for a fence agent supporting these arguments. Successful exploitation results in privilege escalation, first to the service account running the operator and then to another service account with cluster-admin privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share