CVE-2020-14324 is a critical out-of-band OS command injection vulnerability affecting all active versions of Red Hat CloudForms prior to 5.11.7.0. An authenticated attacker can exploit this flaw during conversion host setup within the Infrastructure Migration Solution. With a CVSS score of 9.1, this vulnerability allows for arbitrary command execution on the CloudForms server, posing a significant risk to confidentiality, integrity, and availability. While no public exploits are currently available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.11.7.0CPE matchmatch criteria | cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.