Wazuh, a unified open-source XDR and SIEM platform, contains a critical vulnerability (CVE-2025-24016) affecting versions >= 4.4.0 and < 4.9.1. This issue, stemming from insecure deserialization, allows for Remote Code Execution (RCE) via malicious input to the DistributedAPI. Given its role as a core component in IT security monitoring, the exploitation of this vulnerability poses significant risks to the system’s integrity and availability.
The vulnerability has a CVSS score of 9.9 (Critical) and can be exploited by attackers with valid API credentials. If default credentials are still in use, they can be leveraged to compromise the system. Furthermore, a compromised Wazuh agent could serve as an entry point for the attack. This issue particularly impacts organizations that rely on Wazuh clusters or configurations where agents play key roles.
| Product | Wazuh |
| Date | 2025-02-18 12:36:09 |
| Information |
|
Technical Summary
CVE-2025-24016 stems from the insecure deserialization of DistributedAPI (DAPI) parameters treated as JSON objects. Specifically, the as_wazuh_object function in the Wazuh framework does not properly sanitize inputs. An attacker in possession of valid API credentials can inject a non-sanitized dictionary to exploit this vulnerability, leading to arbitrary Python code execution.
Exploitation Scenarios:
API Access with valid credentials
- The vulnerability can be triggered by sending a malicious request (e.g., via the
run_asendpoint). An attacker with valid credentials can fully control theauth_contextparameter, which is forwarded to the master server for processing. - Default credentials (e.g.,
wazuh-wui:MyS3cr37P450r.*-) significantly increase the risk if they are not changed. - Malicious payloads in such requests lead to RCE on the master server.
- The vulnerability can be triggered by sending a malicious request (e.g., via the
Compromised Agent
- A compromised agent can send a crafted
getconfigresponse containing malicious JSON. - If this request propagates between servers in a cluster, it could cause insecure deserialization on the target server.
- A compromised agent can send a crafted
Technical details:
- The vulnerability originates in the
framework/wazuh/core/cluster/common.pyfile, where theas_wazuh_objectfunction inadequately handles serialized JSON data. - Malicious JSON objects, including those with attributes like
__unhandled_exc__, can execute arbitrary code. - Examples of abuse include injecting
__callable__objects or triggering exception gadgets to further compromise the system.
Recommendations
- Apply the patch immediately
- Update to Wazuh 4.9.1 or later versions, where the vulnerability has been fully resolved. Apply this patch to all affected components, including servers and agents, following the testing and approval processes adopted by your organization.
- Change default credentials
- Ensure that default credentials, such as
wazuh-wui:MyS3cr37P450r.*-, are changed immediately. Use strong, unique passwords for all accounts to prevent unauthorized access.
- Improve monitoring
- Implement logging and detection mechanisms to identify suspicious API requests, particularly toward endpoints like
run_asor DAPI requests. - Monitor for anomalous agent behavior, such as unexpected
getconfigresponses.
- Input sanitization and configuration hardening
- Ensure that all inputs reaching
as_wazuh_objectare properly validated. - Isolate critical components within the Wazuh architecture to limit exploitation paths (e.g., by separating agent communications from API access).
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
