PT-2024-19202 · Icontrol · Icontrol

CVE-2024-22093

·

Published

2024-02-14

·

Updated

2025-09-05

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The issue is related to an authenticated remote command injection in an undisclosed iControl REST endpoint on multi-bladed systems when running in appliance mode. A successful exploit can allow the attacker to cross a security boundary. The affected software is iControl, but the specific versions are not disclosed, except that software versions which have reached End of Technical Support (EoTS) are not evaluated. More information about the exploit can be found at https://t.co/QkeOfBPhqh or https://t.co/tIPZDtnkkz. #iControl #remoteCommandInjection #cybersecurityawareness #infosec #multiBladedSystems #applianceMode #cybersecurity

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04586
CVE-2024-22093

Affected Products

Icontrol