PT-2025-42217 · Vestacp · Vestacp
Published
2025-10-15
·
Updated
2025-10-15
·
CVE-2018-25117
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
VestaCP versions commit a3f0fa1 (2018-05-31) through commit ee03eff (2018-06-13)
Description
The VestaCP installer contained malicious code resulting in a supply-chain compromise. Installations created from the compromised installer since at least May 2018 were subject to the installation of Linux/ChachaDDoS, a multi-stage DDoS bot utilizing Lua for its second- and third-stage components. The compromise resulted in the leakage of administrative credentials, specifically base64-encoded admin passwords and server domains, to an external URL during installation. Additionally, the installer dropped and executed a DDoS malware payload with local system privileges. Compromised servers were observed participating in large-scale DDoS activity. Exploitation in the wild was acknowledged in October 2018.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vestacp