CVE-2024-35164
MEDIUMApache Guacamole < 1.6.0 - Improper Array Index Validation
Title source: ruleDescription
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes could allow arbitrary code to be executed with the privileges of the running guacd process. Users are recommended to upgrade to version 1.6.0, which fixes this issue.
Scores
CVSS v3
6.8
EPSS
0.0004
EPSS Percentile
12.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Classification
CWE
CWE-129
Status
published
Affected Products (1)
apache/guacamole
< 1.6.0
Timeline
Published
Jul 02, 2025
Tracked Since
Feb 18, 2026