CVE-2024-24386

An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
vitalpbxvitalpbx
3.0.4
vitalpbxvitalpbx
3.0.4-2
vitalpbxvitalpbx
3.0.4-4
vitalpbxvitalpbx
3.0.6-1
vitalpbxvitalpbx
3.0.6-2
vitalpbxvitalpbx
3.0.8
vitalpbxvitalpbx
3.0.8:r2
vitalpbxvitalpbx
3.0.8:r3
vitalpbxvitalpbx
3.0.9:r3
vitalpbxvitalpbx
3.0.9:r5
vitalpbxvitalpbx
3.1.0
vitalpbxvitalpbx
3.1.1
vitalpbxvitalpbx
3.1.1:r2
vitalpbxvitalpbx
3.1.1:r3
vitalpbxvitalpbx
3.1.2:r1
vitalpbxvitalpbx
3.1.3:r1
vitalpbxvitalpbx
3.1.4:r1
vitalpbxvitalpbx
3.1.4:r2
vitalpbxvitalpbx
3.1.5:r1
vitalpbxvitalpbx
3.1.5:r2
vitalpbxvitalpbx
3.1.5:r3
vitalpbxvitalpbx
3.1.5:r4
vitalpbxvitalpbx
3.1.6:r1
vitalpbxvitalpbx
3.1.7:r1
vitalpbxvitalpbx
3.2.1
vitalpbxvitalpbx
3.2.2:r1
vitalpbxvitalpbx
3.2.3:r1
vitalpbxvitalpbx
3.2.3:r2
vitalpbxvitalpbx
3.2.3:r4
vitalpbxvitalpbx
3.2.3:r5
vitalpbxvitalpbx
3.2.3:r6
vitalpbxvitalpbx
3.2.3:r7
vitalpbxvitalpbx
3.2.3:r8
vitalpbxvitalpbx
3.2.3:r9
vitalpbxvitalpbx
3.2.4:r1
vitalpbxvitalpbx
3.2.4:r2
vitalpbxvitalpbx
3.2.4:r4
vitalpbxvitalpbx
3.2.4:r5
vitalpbxvitalpbx
3.2.4:r6
vitalpbxvitalpbx
3.2.5:r1
𝑥
= Vulnerable software versions