CVE-2024-47533 is a critical improper authentication vulnerability in Cobbler versions 3.0.0 through 3.2.2 and 3.3.0 through 3.3.6, allowing unauthenticated attackers to gain full control of the server via XML-RPC. With a CVSS score of 9.8, this flaw permits remote attackers to bypass authentication with trivial effort, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists for detection, and the vulnerability has received minimal community discussion or media coverage. Organizations using affected Cobbler versions should upgrade to 3.2.3 or 3.3.7 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cobbler | Cobbler | >= 3.0.0, < 3.2.3, >= 3.3.0, < 3.3.7CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.