docs.aws.amazon.com
https://docs.aws.amazon.com/vpn/latest/clientvpn-user/client-vpn-connect-macos.html CVE-2024-30165
HIGH
Record summary
CVE-2024-30165 has a selected CVSS score of 7.1 (high).
Description
Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions, a different vulnerability than CVE-2024-30164.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 6, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
aws_client_vpnBrowse amazon / aws_client_vpnDefault status: affected | CVE List | Before 3.9.1 | affected |