CVE-2024-5217
KEVmassUnauthenticated RCE in ServiceNow Now Platform (Washington DC, Vancouver, Utah)
CISA: ServiceNow Incomplete List of Disallowed Inputs Vulnerability
CVE-2024-5217 is an input validation flaw — an incomplete list of disallowed inputs (CWE-184/CWE-697) — in ServiceNow's Now Platform, affecting the Washington DC, Vancouver, and earlier releases, with CISA's advisory listing the Utah, Vancouver, and Washington DC releases. Because the flaw is reachable over the network without credentials or user interaction (CVSS 4.0: 9.2 critical, AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker can send crafted input to the platform to trigger it. Successful exploitation yields remote code execution in the context of the Now Platform, with high impact on the confidentiality, integrity, and availability of the instance. Any organization running an affected release is affected, and since Now Platform instances are typically internet-facing, exposure extends beyond internal networks. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2024-07-29 and public reporting indicates cyber agencies have warned that hackers are actively targeting critical ServiceNow vulnerabilities, while EPSS assigns a 99.6% probability of exploitation within 30 days (100th percentile); no public proof-of-concept is known, but the fixes shipped in ServiceNow's June 2024 patching cycle, so unpatched instances remain at risk.
What to do: Inventory all ServiceNow instances, identify those on Washington DC, Vancouver, or earlier releases (including Utah), and apply the relevant June 2024 patching-cycle patches/hot fixes published by ServiceNow immediately, prioritizing internet-facing instances. The flaw is in CISA's KEV catalog (added 2024-07-29) with a 99.6% EPSS score, so treat unpatched instances as actively targeted and, if patching must be delayed, follow vendor mitigation guidance or restrict network access to the instance.
| ServiceNow Now Platform | Washington DC, Vancouver, and earlier releases per the vendor; CISA lists the Utah, Vancouver, and Washington DC Now Platform. Fixed in patches and hot fixes re |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
- Affected
- ServiceNow Utah, Vancouver, and Washington DC Now Platform
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- servicenow
- Products
- servicenow
- Weakness
- CWE-184, CWE-697
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X