libnbd TLS Verification Vulnerability Allows Man-in-the-Middle Attack
CVE-2024-7383
7.4HIGH
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 5 August 2024
Summary
A security flaw exists in libnbd impacting the verification process of the NBD server's certificate during TLS connections. This weakness can lead to a man-in-the-middle attack, compromising the integrity and confidentiality of the NBD traffic. System administrators and users of affected Red Hat products should take immediate actions to apply the necessary updates to mitigate this vulnerability and secure their environments.
Affected Version(s)
Red Hat Enterprise Linux 8 8100020240905091210.489197e6
Red Hat Enterprise Linux 8 8100020240905091210.489197e6
Red Hat Enterprise Linux 9 0:1.18.1-4.el9_4
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jon Szymaniak for reporting this issue.