CVE-2024-2873 is a critical vulnerability affecting wolfSSH server-side state machines prior to version 1.4.17, allowing unauthorized access. A malicious client can bypass user authentication to create channels, leading to high confidentiality and integrity impacts. With a CVSS score of 9.1, this network-exploitable flaw requires no user interaction and has low attack complexity. Currently, there is no public exploit code, active exploitation, or significant community discussion reported for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.17CPE matchmatch criteria | cpe:2.3:a:wolfssh:wolfssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.