MEDIUM · 6.3

CVE-2024-2379

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips t...

Vulnerability Description

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS Score

6.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
HaxxCurl8.6.0
AppleMacos< 12.7.6
NetappActive Iq Unified Manager-
NetappOntap Select Deploy Administration Utility-
NetappH300S Firmware-
NetappH300S-
NetappH410S Firmware-
NetappH410S-
NetappH500S Firmware-
NetappH500S-
NetappH610C Firmware-
NetappH610C-
NetappH610S Firmware-
NetappH610S-
NetappH615C Firmware-
NetappH615C-
NetappH700S Firmware-
NetappH700S-
NetappBootstrap Os-
NetappHci Compute Node-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-2379?

CVE-2024-2379 is a vulnerability with a CVSS score of 6.3 (MEDIUM). libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips t...

How severe is CVE-2024-2379?

CVE-2024-2379 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-2379?

Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Apple Macos, Netapp Active Iq Unified Manager, Netapp Ontap Select Deploy Administration Utility, Netapp H300S Firmware.