CVE-2024-7383

HIGH

Red Hat Enterprise Linux 8 - Improper Certificate Validation in libnbd

Title source: llm
STIX 2.1

Description

A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.

References (6)

Core 6

Scores

CVSS v3 7.4
EPSS 0.0030
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (4)
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 8 8100020240905091210.489197e6
Red Hat/Red Hat Enterprise Linux 8 Advanced Virtualization
Red Hat/Red Hat Enterprise Linux 9 0:1.18.1-4.el9_4
Published Aug 05, 2024
Tracked Since Feb 18, 2026