CVE-2024-2054
CRITICALArticatech Artica Proxy - Insecure Deserialization
Title source: ruleDescription
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
Exploits (3)
metasploit
WORKING POC
EXCELLENT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/artica_proxy_unauth_rce_cve_2024_2054.rb
Scores
CVSS v3
9.8
EPSS
0.8508
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
articatech/artica_proxy
Timeline
Published
Mar 21, 2024
Tracked Since
Feb 18, 2026