logo

Status of Korean Servers Exposed to Grafana Vulnerability (CVE-2024-9264)

ID: 85d6a457-e0b2-5417-b615-a30825bea9a0

STIX ID: report--85d6a457-e0b2-5417-b615-a30825bea9a0

Feed Name: ASEC

Threat Score
80/100

Date Published: 2024-10-24

Date Updated: 2026-04-26

Author: ATCP

...
...

**Executive summary:** AhnLab ASEC warns of a critical Grafana vulnerability (CVE-2024-9264, CVSS 9.9) in Grafana v11.x that allows arbitrary command execution and file disclosure through DuckDB SQL features; public PoC exists and ASEC identified 674 Korean servers on vulnerable v11.x (2,147 servers overall running outdated Grafana). Immediate application of Grafana updates or removing DuckDB from the environment is recommended to mitigate active exploitation risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.