CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2024-6127

Critical · CVSS 9.8

BC Security Empire C2 Framework — Path traversal leading to unauthenticated remote code execution via malicious file upload

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-22, CWE-434

Description

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

Search profile — drives PoC discovery

Symbols Empireagentcryptographic handshakepayload uploadpath traversalstaginglistenertaskresultsuploadfile_uploadagent_comms
Keywords CVE-2024-6127Empire C2 path traversal RCEBC Security Empire unauthenticated RCEEmpire 5.9.3 path traversalEmpire C2 file upload exploitEmpire-C2-RCE-PoCACE-Responder EmpireEmpire C2 CWE-22 CWE-434
Versions: < 5.9.3

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z