CVE-2024-2379 describes a vulnerability in libcurl, specifically when built with wolfSSL, where certificate verification for QUIC connections can be bypassed under certain error conditions related to unknown ciphers or curves. This flaw affects products from Apple, Haxx, and NetApp. Rated Medium severity (CVSS 6.3), it has a network attack vector, low attack complexity, and could lead to low impact on confidentiality, integrity, and availability, requiring user interaction. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.6.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:8.6.0:*:*:*:*:*:*:* | ||
< 12.7.6CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.6.8CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.6CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-2379
Nov 12, 2024CVE-2024-2379
Oct 8, 2024curl: QUIC certificate check bypass with wolfSSL
Mar 27, 2024QUIC certificate check bypass with wolfSSL
Mar 27, 2024QUIC certificate check bypass with wolfSSL
Mar 12, 2024