CVE-2024-36047

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 27, 2025
Updated: Feb 28, 2025
CWE ID 20

Summary

CVE-2024-36047 is a vulnerability affecting Infoblox NIOS versions 8.6.4 and 9.x up to 9.0.3. The issue is rooted in improper input validation, allowing an unauthenticated attacker to send specially crafted malicious data that can be processed as valid. This can lead to arbitrary code execution, potentially enabling attackers to gain administrative control over the affected DNS infrastructure. This vulnerability poses a significant risk, as it can allow attackers to redirect users to phishing sites, intercept and manipulate data, or launch denial-of-service attacks. Infoblox strongly advises users to upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share