CVE-2024-38108 is a critical spoofing vulnerability affecting Microsoft Azure Stack Hub. With a CVSS score of 9.3, it allows unauthenticated attackers to achieve high impact on confidentiality and integrity with low attack complexity, requiring user interaction. While there is no public exploit code or evidence of active exploitation (not in KEV), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2311.1.22CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_stack_hub:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.2311.1.22CPE match | cpe:2.3:a:microsoft:azure_stack_hub:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.