CVE-2024-41124 is a medium-severity vulnerability affecting Puncia, the official CLI utility for Subdomain Center and Exploit Observer. It stems from the utility's use of HTTP instead of HTTPS for API communications, leading to potential eavesdropping, data tampering, unauthorized data access, and Man-in-the-Middle (MITM) attacks. With a CVSS score of 6.3, this vulnerability requires high privileges and user interaction, but an attacker on the adjacent network could achieve high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and the issue has been patched in Puncia version 0.21 by switching to HTTPS.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ARPSyndicate | Puncia | < 0.21CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.8 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.