PT-2024-19202 · Icontrol · Icontrol

Published

2024-02-14

·

Updated

2025-09-05

·

CVE-2024-22093

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The issue is related to an authenticated remote command injection in an undisclosed iControl REST endpoint on multi-bladed systems when running in appliance mode. A successful exploit can allow the attacker to cross a security boundary. The affected software is iControl, but the specific versions are not disclosed, except that software versions which have reached End of Technical Support (EoTS) are not evaluated. More information about the exploit can be found at https://t.co/QkeOfBPhqh or https://t.co/tIPZDtnkkz. #iControl #remoteCommandInjection #cybersecurityawareness #infosec #multiBladedSystems #applianceMode #cybersecurity

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-04586
CVE-2024-22093

Affected Products

Icontrol