CVE-2025-24977
OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the malicious user gets a root shell inside a container this opens up the the infrastructure environment for further attacks and exposures. Version 6.4.11 fixes the issue.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.84%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto secundario
T1552Unsecured Credentialscredential access80 %
CWE-94 (código dinámico) en OpenCTI: usuario con capacidad `manage customizations` ejecuta comandos vía web-hooks. AV:N, PR:H, acceso remoto con privilegios internos→T1210. Impactos: ejecución de comandos en contenedor raíz (T1059), acceso a secretos del servidor (T1552), y escalada/compromiso de in
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-24977",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-24977",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-05T17:39:30.871042Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "OpenCTI-Platform",
"product": "opencti",
"versions": [
{
"status": "affected",
"version": "< 6.4.11"
}
]
}
]
}
],
"published": "2025-05-05T17:18:47.397",
"references": [
{
"url": "https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-mf88-g2wq-p7qm",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the malicious user gets a root shell inside a container this opens up the the infrastructure environment for further attacks and exposures. Version 6.4.11 fixes the issue."
},
{
"lang": "es",
"value": "OpenCTI es una plataforma abierta de inteligencia de ciberamenazas (CTI). Antes de la versión 6.4.11, cualquier usuario con la capacidad de \"gestionar personalizaciones\" podía ejecutar comandos en la infraestructura subyacente donde se alojaba OpenCTI y acceder a secretos internos del servidor mediante el uso indebido de webhooks. Dado que el usuario malicioso obtiene un shell root dentro de un contenedor, esto expone la infraestructura a nuevos ataques y exposiciones. La versión 6.4.11 soluciona este problema."
}
],
"lastModified": "2026-06-17T08:59:55.010",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BDE087C8-44BE-4EFF-A831-9B06999CD8F2",
"versionEndExcluding": "6.4.11",
"versionStartIncluding": "6.4.8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}