CVE-2024-8287

HIGH

Anbox Management Service <1.23.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.

References (3)

Core 3
Core References
Third Party Advisory issue-tracking
https://www.cve.org/CVERecord?id=CVE-2024-8287

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 46.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (1)
canonical/anbox_cloud 1.17.0 - 1.23.1
Published Sep 18, 2024
Tracked Since Feb 18, 2026