CVE-2018-25117 describes a supply-chain compromise in VestaCP installer commits from May to June 2018, embedding malicious code that affected new installations. This critical vulnerability (CVSS 9.3) allowed for the installation of the Linux/ChachaDDoS bot, exfiltration of administrative credentials, and execution of DDoS malware under local system privileges. The attack required user interaction (UI:A) to install the compromised software, leading to severe impacts on confidentiality, integrity, and availability. While Vesta acknowledged exploitation in October 2018, there is no public exploit code, Metasploit module, or significant community discussion, and it is not listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Vesta | Control Panel (CP) | >= a3f0fa1501d424477786e3e7150bb05c0b99518f, < ee03eff016e03cb76fac7ae3a0f9d1ef0f8ee35bCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.