
Proof-of-Concept-Exploit für CVE-2024-8190, eine authentifizierte Command-Injection-Schwachstelle in der Ivanti Cloud Service Appliance, die die Remote-Ausführung von Befehlen auf verwundbaren Geräten ermöglicht.
Proof-of-Concept zur Ausnutzung von CVE-2024-8190 auf verwundbaren Geräten.
Ursache und Indikatoren für eine Kompromittierung finden Sie hier: https://www.horizon3.ai/attack-research/cisa-kev-cve-2024-8190-ivanti-csa-command-injection/
% python3 CVE-2024-8190.py -h
usage: CVE-2024-8190.py [-h] -u URL --username USERNAME --password PASSWORD -c COMMAND
options:
-h, --help show this help message and exit
-u URL, --url URL The base URL of the target
--username USERNAME The application username
--password PASSWORD The application password
-c COMMAND, --command COMMAND
The command to execute blind
Diese Software wurde ausschließlich für akademische Forschungszwecke und zur Entwicklung effektiver Verteidigungstechniken erstellt und ist nicht dazu bestimmt, Systeme anzugreifen, außer wenn dies ausdrücklich autorisiert wurde. Die Projektbetreuer sind nicht verantwortlich oder haftbar für Missbrauch der Software. Nutzen Sie sie verantwortungsbewusst.