CVE-2024-4871
Last modified
CVE-2024-4871 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-4871?
How severe is CVE-2024-4871?
How do I fix CVE-2024-4871?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-48704Phpgurukul Medical Card Generation System v1.0 is vulnerable…6.1
- CVE-2024-48705Wavlink AC1200 with firmware versions M32A3_V1410_230602 and…6.5
- CVE-2024-48706Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) v…5.4
- CVE-2024-48707Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) v…5.4
- CVE-2024-48708Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) v…5.4
- CVE-2024-48709CodeAstro Membership Management System v1.0 is vulnerable to…5.4
- CVE-2024-48710In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin functi…6.5
- CVE-2024-48712In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function hand…6.5
- CVE-2024-48713In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin functio…6.5
- CVE-2024-48714In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function …6.5
- CVE-2024-4872A vulnerability exists in the query validation of the MicroS…8.8
- CVE-2024-48729An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3…7.1
Are you affected by CVE-2024-4871?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
