CVE-2020-24719
23Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 23%
de la publicación al arma0 días
Publicada en NVD12 nov
metasploit20 nov
probabilidad de explotación
23%top 2% de las CVE
explotación observada
noninguna fuente lo reporta
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the magic cookie is included in the content of the logs. An attacker can use the cookie to attach to an Erlang node and run OS level commands on the system running the Erlang node. Affects version: 6.5.1. Fix version: 6.6.0.
Productos afectados
n/a · n/a