An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Woodpecker framework plugin targeting GeoServer instances vulnerable to CVE-2024-3640, a remote code execution vulnerability. The structure includes a main plugin manager, a vulnerability plugin definition, a proof-of-concept (PoC) module for detection, and an exploit module for actual exploitation. The PoC module (GeoserverlRcePoc.java) sends a specially crafted XML payload to the /geoserver/wfs endpoint, using XML comments to obfuscate Java expressions and trigger a time delay, confirming the vulnerability via response time. The exploit module (GeoserverlRceExp.java) allows the user to execute arbitrary commands on the target and optionally inject a memory shell (webshell) for persistent access, also via the /geoserver/wfs endpoint. The plugin is designed for use within the Woodpecker exploitation framework and requires the target GeoServer to be accessible over the network. The repository contains Java source files, a Maven build file, and project configuration files. The main exploit capabilities are remote command execution and memory shell injection, with WAF bypass techniques using XML comment obfuscation.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.