CVE-2024-5651 is a high-severity Remote Code Execution (RCE) vulnerability affecting the Fence Agents Remediation operator. A low-privilege user can exploit this flaw by supplying specially crafted --ssh-path/--telnet-path arguments to execute arbitrary commands on the operator's pod. This vulnerability carries a CVSS score of 8.8 (High) due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Successful exploitation leads to privilege escalation, first to the operator's service account, then to a cluster-admin service account. While not yet confirmed to be actively exploited in the wild (KEV: No), its inclusion on a 'Hot List' suggests close monitoring, though no public exploit code or significant community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Fence Agents Remediation 0.4 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Https://Github.Com/Medik8s/Fence-Agents-Remediation | Fence-Agents-Remediation | >= 0.4.0, < 0.4.1-22CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.