← Global Threat Landscape

CVE-2024-5217

CWE-184

Critical

103.8

RPS

Description

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

Source: NVD

Signals

CVSS
9.8
Critical · v3.1
EPSS
99.62%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Jul 2024
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-184
CWE-184, CWE-697
Published
10 Jul 2024
Last modified 3 Nov 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-5217

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2024-5217 · RPS 103.8 · DevSecure Intelligence