CVE-2024-28249

MEDIUM

Cilium < 1.13.13 - Cleartext Transmission

Title source: rule
STIX 2.1

Description

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue has been resolved in Cilium 1.15.2, 1.14.8, and 1.13.13. There is no known workaround for this issue.

Scores

CVSS v3 6.1
EPSS 0.0030
EPSS Percentile 53.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-319 CWE-311
Status published
Products (2)
cilium/cilium < 1.13.13
cilium/cilium 0 - 1.13.13Go
Published Mar 18, 2024
Tracked Since Feb 18, 2026