CVE-2024-41260

HIGH

netbird management <0.29.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email addresses) when in possession of the audit events database.

Scores

CVSS v3 7.5
EPSS 0.0018
EPSS Percentile 39.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-321
Status published
Products (1)
netbirdio/netbird 0.23.2 - 0.29.2Go
Published Aug 01, 2024
Tracked Since Feb 18, 2026