THREATOPS
THREAT OPSThreat News › CVE-2024-36435 Deep-Dive: The Year's Most Critical BMC Security Flaw

CVE-2024-36435 Deep-Dive: The Year's Most Critical BMC Security Flaw

lowbinarlyPublished 2024-09-26

This vulnerability got our attention for many reasons: firstly, the vendor agreed on the critical impact; and secondly, the nature of the vulnerability where an unauthenticated user can remotely trigger the code flow with a simple post request and cause the arbitrary code execution over classical stack overflow (CWE-121).

Indicators of compromise

Original source: https://www.binarly.io/blog/cve-2024-36435-deep-dive-critical-bmc-security-flaw