CVE-2024-2379
PoC —CVSS 3.1
6.3 medium
EPSS
2%p76
Published
()
Modified
Description
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
- Vendors
- haxxapplenetapp
- Products
- curl, macos, active iq unified manager, ontap select deploy administration utility, h300s firmware, h410s firmware, h500s firmware, h610c firmware, h610s firmware, h615c firmware, h700s firmware, bootstrap os
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.