CVE-2024-24911
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-24911 is a newly identified vulnerability affecting the cpca process on Security Management Servers and Domain Management Servers. In specific conditions, this process may unexpectedly terminate, resulting in a core dump file. The consequences of this issue can lead to VPN and SIC connectivity problems if the Certificate Revocation List (CRL) is not available in the Security Gateway's CRL cache. This vulnerability does not pose a risk in typical system configurations where the CRL is consistently updated. However, in rare instances when the CRL is not present, the unexpected exit of the cpca process could cause connectivity disruptions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.