A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
References
Configurations
No configuration.
History
25 Sep 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Sep 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
06 Aug 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.4 |
05 Aug 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-05 14:15
Updated : 2024-09-25 01:15
NVD link : CVE-2024-7383
Mitre link : CVE-2024-7383
CVE.ORG link : CVE-2024-7383
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation