CVE-2024-49214
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Oct 14, 2024
Updated: Oct 29, 2024
CWE ID 290
Summary
CVE-2024-49214 is a cybersecurity vulnerability affecting HAProxy versions 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11. Malicious actors can exploit this issue by initiating a 0-RTT (Zero Round-Trip Time) session with a spoofed IP address. This bypasses the IP allow/block list functionality, allowing unauthorized access to the targeted network or system. The vulnerability lies within the QUIC protocol implementation in HAProxy, enabling attackers to evade security measures relying on IP address filtering.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- HAProxy
Affected Vendors
- Haproxy