ZeroHour

CVE-2024-2379

PoC
CVSS 3.1
6.3 medium
EPSS
2%p76
Published
()
Modified
Description

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

Vendors
haxxapplenetapp
Products
curl, macos, active iq unified manager, ontap select deploy administration utility, h300s firmware, h410s firmware, h500s firmware, h610c firmware, h610s firmware, h615c firmware, h700s firmware, bootstrap os
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.