Over 660,000 Rsync servers exposed to code execution attacks
ID: f930241f-59e7-5802-8f21-f70385fa0d2f
STIX ID: report--f930241f-59e7-5802-8f21-f70385fa0d2f
Feed Name: Bleeping Computer
Threat Score
The report details six vulnerabilities in Rsync (notably CVE-2024-12084, a critical heap-buffer overflow with CVSS 9.8 allowing remote code execution with anonymous read access) affecting all versions below 3.4.0; it warns of widespread exposure (over 660,000 public Rsync servers found), lists affected vendors/OSes, and urges immediate upgrades to 3.4.0 or blocking port 873/configuring authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
