CVE-2024-49214

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 14, 2024
Updated: Oct 29, 2024
CWE ID 290

Summary

CVE-2024-49214 is a cybersecurity vulnerability affecting HAProxy versions 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11. Malicious actors can exploit this issue by initiating a 0-RTT (Zero Round-Trip Time) session with a spoofed IP address. This bypasses the IP allow/block list functionality, allowing unauthorized access to the targeted network or system. The vulnerability lies within the QUIC protocol implementation in HAProxy, enabling attackers to evade security measures relying on IP address filtering.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share