CVE-2024-35164
MEDIUMApache Guacamole < 1.6.0 - Remote Code Execution via Terminal Emulator Console Code Injection
Title source: llmDescription
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes could allow arbitrary code to be executed with the privileges of the running guacd process. Users are recommended to upgrade to version 1.6.0, which fixes this issue.
References (2)
Core 2
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/sgs8lplbkrpvd3hrvcnnxh3028h4py70
Scores
CVSS v3
6.8
EPSS
0.0043
EPSS Percentile
33.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-129
Status
published
Products (1)
apache/guacamole
0.8.0 - 1.6.0
Published
Jul 02, 2025
Tracked Since
Feb 18, 2026