CVE-2024-8287
Last modified
CVE-2024-8287 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Anbox Cloud | >= 1.17.0, < 1.23.1 |
References
- https://bugs.launchpad.net/anbox-cloud/+bug/2077570Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-8287Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-8287?
How severe is CVE-2024-8287?
How do I fix CVE-2024-8287?
Are you affected by CVE-2024-8287?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
