THREAT OPS › Threat News › CVE-2024-36435 Deep-Dive: The Year's Most Critical BMC Security Flaw
CVE-2024-36435 Deep-Dive: The Year's Most Critical BMC Security Flaw
This vulnerability got our attention for many reasons: firstly, the vendor agreed on the critical impact; and secondly, the nature of the vulnerability where an unauthenticated user can remotely trigger the code flow with a simple post request and cause the arbitrary code execution over classical stack overflow (CWE-121).
Indicators of compromise
- CVE-2024-36435cve