CVE-2024-5732
Last modified
CVE-2024-5732 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the component Proxy Port. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. VDB-267406 is the identifier assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Clashforwindows | Clash | >= 0.1.0, <= 0.20.1 |
References
- https://github.com/GTA12138/vul/blob/main/clash%20for%20windows.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.267406Permissions Required, VDB Entry
- https://vuldb.com/?id.267406Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.345469Third Party Advisory, VDB Entry
- https://github.com/GTA12138/vul/blob/main/clash%20for%20windows.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.267406Permissions Required, VDB Entry
- https://vuldb.com/?id.267406Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.345469Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-5732?
How severe is CVE-2024-5732?
How do I fix CVE-2024-5732?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-57278A reflected Cross-Site Scripting (XSS) vulnerability exists …5.4
- CVE-2024-57279A reflected Cross-Site Scripting (XSS) vulnerability has bee…5.4
- CVE-2024-5728The Animated AL List WordPress plugin through 1.0.6 does not…5.4
- CVE-2024-5729The Simple AL Slider WordPress plugin through 1.2.10 does no…6.1
- CVE-2024-5730The Pagerank tools WordPress plugin through 1.1.5 does not s…6.1
- CVE-2024-5731A vulnerability in the IPS Manager, Central Manager, and Loc…6.8
- CVE-2024-57326A Reflected Cross-Site Scripting (XSS) vulnerability exists …6.1
- CVE-2024-57328A SQL Injection vulnerability exists in the login form of On…9.8
- CVE-2024-57329HortusFox v3.9 contains a stored XSS vulnerability in the "A…5.4
- CVE-2024-5733A vulnerability was found in itsourcecode Online Discussion …9.8
- CVE-2024-57336Incorrect access control in M2Soft CROWNIX Report & ERS affe…6.5
- CVE-2024-57337An arbitrary file upload vulnerability in the opcode 500 fun…6.5
Are you affected by CVE-2024-5732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
