CVE-2024-47533 is an improper authentication vulnerability in Cobbler, a Linux installation server used to manage network-based system deployments. The flaw affects Cobbler starting in version 3.0.0 and prior to fixed versions 3.2.3 and 3.3.7. The vulnerable condition is caused by the authentication-related function utils.get_shared_secret() always returning the constant value -1 instead of a valid shared secret. As a result, an attacker can authenticate to the Cobbler XML-RPC interface using an empty username and the password -1, bypassing intended access controls. Because the XML-RPC interface permits administrative changes, successful exploitation gives an unauthenticated remote attacker the ability to perform arbitrary modifications through Cobbler's management functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2024-47533, a critical authentication bypass vulnerability in Cobbler, a Linux network installation server. The exploit is implemented in a single Python script (CVE-2024-47533.py) that targets Cobbler's XML-RPC API. By exploiting a logic flaw in authentication, the script logs in with an empty username and a password of -1, gaining administrator access. It then creates or uses a minimal Cobbler distro and profile, uploads a malicious kickstart template containing a reverse shell payload, and triggers Cobbler to render the template, resulting in remote code execution on the server. The payload opens a reverse shell to the attacker's specified host and port. The repository also includes a README.md with a detailed description of the vulnerability, affected versions, and usage disclaimer. The exploit requires the attacker to know the Cobbler XML-RPC endpoint and to have a listener ready to catch the reverse shell. The main attack vector is network-based, targeting the Cobbler XML-RPC API.
This repository contains a working exploit for CVE-2024-47533, a critical authentication bypass and remote code execution vulnerability in Cobbler (versions 3.0.0 up to but not including 3.2.3 and 3.3.7). The exploit is implemented in a single Python script (CVE-2024-47533.py) and is accompanied by a detailed README.md. The exploit abuses Cobbler's XMLRPC API, which can be accessed without authentication due to a logic flaw in the shared secret function. The script allows the attacker to specify the target Cobbler server, their own IP and port for a reverse shell, and the payload type (bash, nc, or curl). Upon execution, the script sends a malicious import request to the Cobbler API, resulting in arbitrary command execution and a reverse shell connection to the attacker's listener. The main attack vector is network-based, targeting the XMLRPC API endpoint (typically http://<target>:25151/). The repository is well-structured, with clear usage instructions and technical details in the README.
This repository contains a proof-of-concept exploit for CVE-2024-47533, a critical authentication bypass vulnerability in Cobbler's XML-RPC API. The exploit is implemented in a single Python script (CVE-2024-47533.py) and is accompanied by a detailed README.md. The exploit works by abusing a flaw in Cobbler's authentication logic, allowing an attacker to authenticate with an empty username and a password of -1. Once authenticated, the script injects a bash reverse shell command via the 'name' parameter of the background_import API call, resulting in unauthenticated remote code execution on the Cobbler server. The attacker must provide the target's XML-RPC endpoint URL, their own IP address, and a listening port for the reverse shell. The attack vector is network-based, requiring only access to the exposed Cobbler XML-RPC API. The exploit targets Cobbler versions 3.0.0 up to (but not including) 3.2.3 and 3.3.0 up to (but not including) 3.3.7, running on Linux. No fake or destructive code is present; the exploit is a functional PoC for educational and research purposes.
This repository contains a working exploit for CVE-2024-47533, a critical authentication bypass and remote code execution vulnerability in Cobbler (versions 3.0.0 up to but not including 3.2.3 and 3.3.7). The exploit is implemented in a single Python script (CVE-2024-47533-dbs.py) and is accompanied by a detailed README.md. The exploit abuses the Cobbler XMLRPC API, which listens by default on http://<target>:25151/. By exploiting a logic flaw in authentication, the script can execute arbitrary shell commands on the target server. The script supports multiple reverse shell payloads (bash, nc, python, curl, etc.), allowing the attacker to gain a remote shell on the vulnerable server. The README provides technical background, usage instructions, and references. The exploit is operational and provides a real shell if the target is vulnerable and accessible.
This repository contains a Python exploit script (CVE-2024-47533.py) targeting Cobbler servers vulnerable to CVE-2024-47533, an authentication bypass in the XML-RPC API. The exploit connects to the Cobbler XML-RPC endpoint, creates or reuses a distribution and profile, and writes a malicious autoinstall template containing a Cheetah expression that executes arbitrary system commands. The script then triggers the server to render the template, resulting in command execution on the Cobbler server. The README provides usage examples for reverse shells, command execution, and SSH key drops. The exploit is operational, requiring the attacker to specify the target URL and command. The main attack vector is network-based, targeting the Cobbler XML-RPC API. Fingerprintable endpoints include the default API URL, file paths used in the exploit, and the SSH authorized_keys file for persistence.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authentication bypass vulnerability in Cobbler caused by get_shared_secret() returning a fixed value (-1), allowing unauthorized access to the XML-RPC interface and full control of affected servers.
A critical improper authentication vulnerability in Cobbler Server that allows unauthenticated network attackers to connect to the Cobbler XML-RPC interface using a default-like invalid shared secret value and gain full control of the server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.