CVE-2024-53304
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-53304 is a newly disclosed vulnerability affecting the LRQA Nettitude PoshC2 tool. This issue enables unauthenticated attackers to join the command and control (C2) server and execute arbitrary commands. The vulnerability is exploited by an attacker posing as an infected machine, bypassing authentication requirements. This poses a significant risk, as attackers can gain unauthorized access and control over the targeted system. The specific cause of this vulnerability lies within the LRQA Nettitude PoshC2 software after the commit 09ee2cf. Users are strongly advised to apply patches or updates as soon as they become available to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.