CVE-2024-12777
CVSS 3.0 Score 5.9 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 1088
Summary
CVE-2024-12777 is a denial-of-service vulnerability affecting aimhubio/aim version 3.25.0. The issue lies in the misuse of the sshfs-client, which can cause the tracking server to become unresponsive. Since the server is single-threaded, it becomes unresponsive when it attempts to connect to an unresponsive socket via sshfs. Unfortunately, the sshfs-client lacks a timeout setting, causing the server to hang for an extended period and rendering it unable to process other requests.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aim