← volver
CVE-2018-25320

ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Execution

CVSS 9.3 CRITICALEPSS 0.6%CWE-94
Vexday Risk Score
48Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 9.3EPSS 0.6%KEV nãoPoC públicaNuclei Metasploit Patch
Ciclo de vida
17 may 2026Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
acl · ACL Analytics
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.