Coder Social home page Coder Social logo

nettitude / cve-2024-20356 Goto Github PK

View Code? Open in Web Editor NEW
43.0 6.0 8.0 22 KB

This is a proof of concept for CVE-2024-20356, a Command Injection vulnerability in Cisco's CIMC.

Home Page: https://labs.nettitude.com/blog/cve-2024-20356-jailbreaking-a-cisco-appliance-to-run-doom

License: GNU General Public License v3.0

Python 100.00%
cimc cisco cve-2024-20356

cve-2024-20356's Introduction

CVE-2024-20356

This is a proof of concept for CVE-2024-20356, a Command Injection vulnerability in Cisco's CIMC.

Full technical details can be found at https://labs.nettitude.com/blog/cve-2024-20356-jailbreaking-a-cisco-appliance-to-run-doom

Usage

Usage: CVE-2024-20356.py [-h] -t HOST -u USERNAME -p PASSWORD [-a ACTION] [-c CMD] [-v]
options:
  -h, --help            Show this help message and exit
  -t HOST, --host HOST  Target hostname or IP address (format 10.0.0.1 or 10.0.0.2:1337)
  -u USERNAME, --username USERNAME
                        Username (default: admin)
  -p PASSWORD, --password PASSWORD
                        Password (default: cisco)
  -a ACTION, --action ACTION
                        Action: test, cmd, shell, dance (default: test)
  -c CMD, --cmd CMD     OS command to run (Default: NONE)
  -v, --verbose         Displays more information about cimc

Example commands:

CVE-2024-20356.py --host 192.168.x.x -u admin -p your_password -v
CVE-2024-20356.py --host 192.168.x.x -u admin -p your_password -c 'id'
CVE-2024-20356.py --host 192.168.x.x -u admin -p your_password -a shell
CVE-2024-20356.py --host 192.168.x.x -u admin -p your_password -a dance

Use the --help argument for full usage instructions.

Disclaimer

This proof-of-concept is for demonstration purposes and should not be used for illegal activities. LRQA Nettitude are not responsible for any damage caused by the use or misuse of this code.

cve-2024-20356's People

Contributors

thackeraaron avatar

Stargazers

aubrey avatar  avatar oldkingcone avatar Postmodern avatar 1nv0k3r avatar  avatar henhao avatar Beta avatar  avatar StudioSEO avatar nobgr avatar  avatar Amine Elsassi avatar Birdo avatar Ihebski avatar  avatar Huy (Valen) Võ avatar  avatar  avatar  avatar  avatar  avatar  avatar 面向大海 avatar Martin Kylian avatar Jd avatar  avatar Achmad Adhikara avatar  avatar xrkk avatar  avatar ccoday avatar Tripp avatar Aldo Adirajasa Fathoni avatar Mohammad Iqbal Ahmad avatar Ronan Kervella avatar Garam Lee avatar  avatar Giordano avatar Darren avatar Rahmad Sandy avatar DummyKitty avatar ddos avatar

Watchers

Iain Wallace avatar Chris Oakley avatar Ben Turner avatar Graham Shaw avatar Tom Wedgbury avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.