PT-2025-16874 · Lrqa Nettitude · Poshc2

Published

2025-04-16

·

Updated

2025-04-20

·

CVE-2024-53304

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LRQA Nettitude PoshC2 versions after commit 09ee2cf
Description The issue allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands by posing as an infected machine.
Recommendations For versions after commit 09ee2cf, consider restricting access to the C2 server as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-53304

Affected Products

Poshc2