### [CVE-2024-38324](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38324) ![](https://img.shields.io/static/v1?label=Product&message=Storage%20Defender%20-%20Resiliency%20Service&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=2.0.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-297%20Improper%20Validation%20of%20Certificate%20with%20Host%20Mismatch&color=brightgreen) ### Description IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds