CVE-2024-53304

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 284

Summary

CVE-2024-53304 is a newly disclosed vulnerability affecting the LRQA Nettitude PoshC2 tool. This issue enables unauthenticated attackers to join the command and control (C2) server and execute arbitrary commands. The vulnerability is exploited by an attacker posing as an infected machine, bypassing authentication requirements. This poses a significant risk, as attackers can gain unauthorized access and control over the targeted system. The specific cause of this vulnerability lies within the LRQA Nettitude PoshC2 software after the commit 09ee2cf. Users are strongly advised to apply patches or updates as soon as they become available to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share