CVE-2024-8504 is a critical vulnerability in VICIdial that allows an authenticated agent to execute arbitrary shell commands as the root user. This high-severity flaw (CVSS 8.8) can be chained with CVE-2024-8503 for unauthenticated remote code execution, posing a significant risk of complete system compromise. While not currently observed in active exploitation, a Metasploit module exists, indicating readily available exploit code. Despite its high EPSS and FAUCET Risk Score, there is currently minimal public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| VICIdial | VICIdial | 2.14-917aCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.