Article

    Cyber News / Article / CVE-2022-44877, critical RCE in CentOS Control Web Panel exploited in the wild: everything you need to know

    CVE-2022-44877, critical RCE in CentOS Control Web Panel exploited in the wild: everything you need to know
    Me
    Merav Bar-2023-01-17

    CVE-2022-44877, critical RCE in CentOS Control Web Panel exploited in the wild: everything you need to know

    Detect and mitigate CVE-2022-44877, a CentOS Control Web Panel (CWP) unauthenticated RCE exploited in the wild. Security teams are advised to patch urgently.

    CVE-2022-44877, a critical RCE vulnerability in Control Web Panel 7 (also known as CentOS Web Panel), has been reportedly exploited in the wild. The vulnerability could allow an unauthenticated attacker to escalate privileges and execute code remotely on susceptible servers. Although the vulnerability was published and assigned a CVE on January 6, a fix has been available since October 25, 2022. It was assigned a CVSS score of 9.8.

    Exploitation attempts reportedly began around January 6, closely following the publication of a publicproof of concept.

    In unpatched versions of CWP, there is a flaw that allows the execution of Bash commands if double quotation marks are used when logging incorrect entries into the system. This flaw could enable an attacker to execute commands remotely on a machine running a vulnerable version of CWP, with the same privilege level as CWP, which in many cases isrootby default. This is the third critical vulnerability in CWP published in the past 30 days, along withCVE-2021-45467andCVE-2021-45466.

    According to Wiz data, CWP is not prevalent in cloud environments and therefore there is a lower risk of CVE-2022-44877 exploitation in such environmets.

    Since the publication of the proof of concept on January 6,mass exploitationattempts have beenobservedin the wild.

    See the full post on

    Researchers observedthe following IP addresses in attempted exploitations:

    206.189.170.136

    185.117.73.208

    157.230.62.113

    180.183.132.35

    See the full post on

    Versions of CentOS Control Web Panel prior to version0.9.8.1147.

    It is highly recommended to update instances of CWP to the patched version0.9.8.1147, or later. In addition, monitor if your environments have been accessed by any aboveknown malicious IP address.

    Wiz customers can use the pre-built query and advisory in the Wiz Threat Center to search for vulnerable instances in their environment.

    CloudSEK blog

    The Hacker News article

    Proof of concept

    Learn how to detect malicious persistence techniques in AWS, GCP & Azure after potential initial compromise, like with the CircleCI incident

    Wiz announces availability of new regional data center and adds support for Essential Eight controls.

    Hear from security leaders about their plans, strategies, and priorities for the new year.

    Get a personalized demo

    ©2026Wiz, Inc.

    StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings

    Original source