HomeHaxxCVE-2024-2379

CVE-2024-2379

MEDIUM
6.3CVSS
Published: 2024-03-27
Updated: 2025-07-30
AI Analysis

Description

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
low
Integrity
low
Availability
low
Weaknesses
CWE-295

Metadata

Primary Vendor
HAXX
Published
3/27/2024
Last Modified
7/30/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

haxx : curlapple : macosapple : macosapple : macosnetapp : active_iq_unified_managernetapp : ontap_select_deploy_administration_utilitynetapp : h300s_firmwarenetapp : h410s_firmwarenetapp : h500s_firmwarenetapp : h610c_firmwarenetapp : h610s_firmwarenetapp : h615c_firmwarenetapp : h700s_firmwarenetapp : bootstrap_os

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-2379 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com