CVE-2024-52288
CVSS 3.1 Score 5.1 of 10 (medium)
Details
Summary
CVE-2024-52288 is a vulnerability affecting libosdp, an Open Supervised Device Protocol (OSCP) implementation. In affected versions, unexpected `REPLY_CCRYPT` or `REPLY_RMAC_I` messages can be introduced into an active stream, enabling a man-in-the-middle (MITM) attacker to record and replay all messages exchanged during a session. Once the attacker intercepts the message to be replied, they can craft a specific RMAC_I message to revert the session to the beginning, allowing them to replay all previous messages. The vulnerability is fixed in commit `298576d9`, included in release version 3.0.0. Users are urged to upgrade as no workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.