CVE-2024-12777

CVSS 3.0 Score 5.9 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 1088

Summary

CVE-2024-12777 is a denial-of-service vulnerability affecting aimhubio/aim version 3.25.0. The issue lies in the misuse of the sshfs-client, which can cause the tracking server to become unresponsive. Since the server is single-threaded, it becomes unresponsive when it attempts to connect to an unresponsive socket via sshfs. Unfortunately, the sshfs-client lacks a timeout setting, causing the server to hang for an extended period and rendering it unable to process other requests.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share