CVE-2024-2379
MEDIUMHaxx Curl < 12.7.6 - Improper Certificate Validation
Title source: ruleDescription
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
References (11)
Scores
CVSS v3
6.3
EPSS
0.0021
EPSS Percentile
42.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Classification
CWE
CWE-295
Status
published
Affected Products (12)
haxx/curl
apple/macos
< 12.7.6
netapp/active_iq_unified_manager
netapp/ontap_select_deploy_administration_utility
netapp/h300s_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h610c_firmware
netapp/h610s_firmware
netapp/h615c_firmware
netapp/h700s_firmware
netapp/bootstrap_os
Timeline
Published
Mar 27, 2024
Tracked Since
Feb 18, 2026