CVE-2024-32473

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Apr 18, 2024
Updated: Apr 19, 2024
CWE ID 668

Summary

CVE-2024-32473 is a vulnerability in Moby, an open-source container framework used in Docker Engine and Docker Desktop. In version 26.0.0, IPv6 is not disabled on network interfaces, even when the `--ipv6=false` flag is used. This allows containers with `ipvlan` or `macvlan` interfaces to have direct access to the host machine's network link, increasing the attack surface of IPv4-only networks. The vulnerability can lead to unauthorized communication with other hosts on the local network and potential SLAAC-assigned addresses for containers. To mitigate this issue, users should update to version 26.0.2 and completely disable IPv6 in containers using `--sysctl=net.ipv6.conf.all.disable_ipv6=1` during container creation. The vulnerability has a base severity rating of MEDIUM and a CVSS score of 4.7, with high confidentiality impact but no integrity or availability impact.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-32473 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions