CVE-2024-41628

HIGH NUCLEI

Severalnines Cluster Control <2.1.0 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-41628. PoCs published by Redshift-CyberSecurity. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a functional Python script that exploits CVE-2024-41628, a Local File Inclusion (LFI) vulnerability in ClusterControl's CMON API. The exploit targets ports 9500 (HTTP) and 9501 (HTTPS) to retrieve arbitrary system files by leveraging directory traversal sequences.

Description

Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.

Exploits (1)

nomisec WORKING POC 2 stars
by Redshift-CyberSecurity · poc
https://github.com/Redshift-CyberSecurity/CVE-2024-41628

The repository contains a functional Python script that exploits CVE-2024-41628, a Local File Inclusion (LFI) vulnerability in ClusterControl's CMON API. The exploit targets ports 9500 (HTTP) and 9501 (HTTPS) to retrieve arbitrary system files by leveraging directory traversal sequences.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ClusterControl versions 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780
No auth needed
Prerequisites: Network access to the target's RPC or RPC-TLS interface (ports 9500 or 9501)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Nuclei Templates (1)

Cluster Control CMON API - Directory Traversal
HIGHby s4e-io
FOFA: icon_hash="160707013" || icon_hash="-1815707560"

Scores

CVSS v3 7.5
EPSS 0.0646
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Published Jul 26, 2024
Tracked Since Feb 18, 2026