logo

Over 660,000 Rsync servers exposed to code execution attacks

ID: f930241f-59e7-5802-8f21-f70385fa0d2f

STIX ID: report--f930241f-59e7-5802-8f21-f70385fa0d2f

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-01-15

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

The report details six vulnerabilities in Rsync (notably CVE-2024-12084, a critical heap-buffer overflow with CVSS 9.8 allowing remote code execution with anonymous read access) affecting all versions below 3.4.0; it warns of widespread exposure (over 660,000 public Rsync servers found), lists affected vendors/OSes, and urges immediate upgrades to 3.4.0 or blocking port 873/configuring authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.