EXECUTIVE SUMMARY:
Two critical vulnerabilities have been identified with evidence of active exploitation. The first, CVE-2024-5910, is a missing authentication flaw in a migration tool, enabling attackers to take over admin accounts and access sensitive data. The second, CVE-2024-51567, impacts CyberPanel, allowing remote attackers to execute commands as root without authentication. This vulnerability has been exploited in ransomware attacks, targeting numerous exposed CyberPanel instances.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Two critical vulnerabilities have been identified with evidence of active exploitation. The first, CVE-2024-5910, is a missing authentication flaw in a migration tool, enabling attackers to take over admin accounts and access sensitive data. The second, CVE-2024-51567, impacts CyberPanel, allowing remote attackers to execute commands as root without authentication. This vulnerability has been exploited in ransomware attacks, targeting numerous exposed CyberPanel instances.[emaillocker id="1283"]
Prompt remediation of these critical vulnerabilities is essential to prevent unauthorized access, data compromise, and ransomware attacks. Strengthening defenses against these threats will significantly enhance network security.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/11/cisa-alerts-to-active-exploitation-of.html