CVE-2024-6284 Vulnerability Details

  /     /     /  

CVE-2024-6284 Metadata Quick Info

CVE Published: 03/07/2024 | CVE Updated: 19/08/2024 | CVE Year: 2024
Source: Google | Vendor: Google | Product: https://github.com/google/nftables
Status : PUBLISHED

CVE-2024-6284 Description

In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue affects:  https://pkg.go.dev/github.com/google/nftables@v0.1.0 The bug was fixed in the next released version:  https://pkg.go.dev/github.com/google/nftables@v0.2.0

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-20
CWE Name: CWE-20 Improper Input Validation
Source: Google

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-180
CAPEC Description: CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels


Source: NVD (National Vulnerability Database).