2024-12-08 03:06:42 +00:00

80 lines
2.4 KiB
JSON

{
"id": "CVE-2024-2873",
"sourceIdentifier": "facts@wolfssl.com",
"published": "2024-03-25T22:37:19.847",
"lastModified": "2024-11-21T09:10:43.603",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.\n"
},
{
"lang": "es",
"value": "Se encontr\u00f3 una vulnerabilidad en la m\u00e1quina de estado del lado del servidor de wolfSSH antes de las versiones 1.4.17. Un cliente malintencionado podr\u00eda crear canales sin realizar primero la autenticaci\u00f3n del usuario, lo que provocar\u00eda un acceso no autorizado."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "facts@wolfssl.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "facts@wolfssl.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"references": [
{
"url": "https://github.com/wolfSSL/wolfssh/pull/670",
"source": "facts@wolfssl.com"
},
{
"url": "https://github.com/wolfSSL/wolfssh/pull/671",
"source": "facts@wolfssl.com"
},
{
"url": "https://www.wolfssl.com/docs/security-vulnerabilities/",
"source": "facts@wolfssl.com"
},
{
"url": "https://github.com/wolfSSL/wolfssh/pull/670",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/wolfSSL/wolfssh/pull/671",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.wolfssl.com/docs/security-vulnerabilities/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}