Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-5651

27
FAUCET Score

CVE-2024-5651 is a high-severity Remote Code Execution (RCE) vulnerability affecting the Fence Agents Remediation operator. A low-privilege user can exploit this flaw by supplying specially crafted --ssh-path/--telnet-path arguments to execute arbitrary commands on the operator's pod. This vulnerability carries a CVSS score of 8.8 (High) due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Successful exploitation leads to privilege escalation, first to the operator's service account, then to a cluster-admin service account. While not yet confirmed to be actively exploited in the wild (KEV: No), its inclusion on a 'Hot List' suggests close monitoring, though no public exploit code or significant community discussion has been observed.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatFence Agents Remediation 0.4 For RHEL 8
Range not provided by sourceCNA affecteddefault affected
Https://Github.Com/Medik8s/Fence-Agents-RemediationFence-Agents-Remediation
>= 0.4.0, < 0.4.1-22CNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.37%
Probability of exploitation in next 30 days
EPSS Percentile
69.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0137 is in the 66th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Fence Agents Remediation 0.4 for RHEL 8Fixed in: workload-availability/fence-agents-remediation-operator-bundle:v0.4.1-22
View patch
redhatpatch availablevia redhat_api
Product: Fence Agents Remediation 0.4 for RHEL 8Fixed in: workload-availability/fence-agents-remediation-rhel8-operator:v0.4.1-22
View patch

Vendor Advisories (1)

redhatCVE-2024-5651Important

fence-agents-remediation: Fence Agent Command Line Options Leads to Remote Code Execution

Aug 12, 2024

References

access.redhat.com / errata/RHSA-2024:5453
access.redhat.com / security/cve/CVE-2024-5651
bugzilla.redhat.com / show_bug.cgi