Cilium Vulnerable to Cryptographic Attacks
CVE-2024-28860
What is CVE-2024-28860?
Cilium, an innovative networking and security solution utilizing eBPF, has a vulnerability that can be exploited when users implement IPsec transparent encryption. Specifically, this flaw exposes users to various attacks, including chosen plaintext, key recovery, and replay attacks conducted by a man-in-the-middle. The core issue arises from ESP sequence number collisions due to multiple nodes sharing the same encryption key. This weakness can potentially compromise encrypted data. To mitigate this vulnerability, updated versions of Cilium have been released, employing unique keys for each IPsec tunnel between nodes, effectively closing off possible attack vectors.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cilium >= 1.4.0, <= 1.13.14 <= 1.4.0, 1.13.14
cilium >= 1.14.0, < 1.14.9 < 1.14.0, 1.14.9
cilium >= 1.15.0, < 1.15.3 < 1.15.0, 1.15.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
