MEDIUM · 6.5

CVE-2024-2466

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when ...

Vulnerability Description

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
HaxxCurl>= 8.5.0, < 8.7.0
AppleMacos< 12.7.6
NetappH700S Firmware-
NetappH700S-
NetappBootstrap Os-
NetappHci Compute Node-
NetappH300S Firmware-
NetappH300S-
NetappH410S Firmware-
NetappH410S-
NetappH500S Firmware-
NetappH500S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-2466?

CVE-2024-2466 is a vulnerability with a CVSS score of 6.5 (MEDIUM). libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when ...

How severe is CVE-2024-2466?

CVE-2024-2466 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-2466?

Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Apple Macos, Netapp H700S Firmware, Netapp H700S, Netapp Bootstrap Os.