CVE-2025-4971
HIGHBroadcom Automic Automation Agent Unix <24.3.0 HF4-21.0.13 HF1 - Pr...
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-4971. PoCs published by Flora Schäfer.
AI-analyzed exploit summary This exploit leverages a privilege escalation vulnerability in Automic Agent by injecting a malicious shared object file via configuration parameters. The exploit uses msfvenom to generate a malicious .so file that spawns a shell with elevated privileges when loaded by the vulnerable executable.
Description
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.
Exploits (1)
This exploit leverages a privilege escalation vulnerability in Automic Agent by injecting a malicious shared object file via configuration parameters. The exploit uses msfvenom to generate a malicious .so file that spawns a shell with elevated privileges when loaded by the vulnerable executable.
References (2)
Scores
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L