Impact
Apache CloudStack permits authenticated administrators to invoke getDiagnosticsData or runDiagnostics APIs. Because these endpoints fail to neutralize special elements properly, they are vulnerable to command injection. An attacker with administrative privileges can execute arbitrary shell commands on the underlying system VM or virtual router as root or the diagnostics-process user, granting full control over the instance and potential lateral movement within the CloudStack environment.
Affected Systems
Apache CloudStack versions 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 are affected. All builds within these version ranges contain the vulnerability. The issue is limited to API endpoints that require administrator permissions.
Risk and Exploitability
The high CVSS score of 8.8 reflects the impact of arbitrary command execution as root. The EPSS score is 1%, indicating a moderate probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. The vulnerability is exploitable via the management server’s API, over the network. The likely attack vector is an authenticated API call to getDiagnosticsData or runDiagnostics, as inferred from the description. An attacker with administrative privileges could execute commands on system VMs or virtual routers. Based on the description, it is inferred that environments with shared or weak admin credentials would be at increased risk.
OpenCVE Enrichment