← Back to browse
·
API
CVE-2024-39844
Severity
CRITICAL
CVSS
9.8
EPSS
0.03862
Risk score
40.55
CISA KEV
No
PoC
No
Published
2024-07-03
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-38265, GHSA-QH94-PJXQ-88V7
Products
n/a:n/a n/a
Sources
euvd
EUVD-2024-38265
Description
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-38265
https://wiki.znc.in/Category:ChangeLog
https://github.com/znc/znc/releases/tag/znc-1.9.1
https://wiki.znc.in/ChangeLog/1.9.1
https://www.openwall.com/lists/oss-security/2024/07/03/9
http://www.openwall.com/lists/oss-security/2024/07/03/9