1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["12757"],{773676:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>c,toc:()=>a,default:()=>h,metadata:()=>s,assets:()=>d,contentTitle:()=>l});var s=JSON.parse('{"id":"security-bulletins/reports/vc-cve-2024-3596","title":"CVE-2024-3596","description":"Lifecycle of CVE-2024-3596","source":"@site/docs/docs-content/security-bulletins/reports/vc-cve-2024-3596.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/vc-cve-2024-3596","permalink":"/security-bulletins/reports/vc-cve-2024-3596","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/vc-cve-2024-3596.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2024-3596","title":"CVE-2024-3596","description":"Lifecycle of CVE-2024-3596","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2024-28757","permalink":"/security-bulletins/reports/vc-cve-2024-28757"},"next":{"title":"CVE-2024-3651","permalink":"/security-bulletins/reports/vc-cve-2024-3651"}}'),r=i(474848),n=i(884429);let c={sidebar_label:"CVE-2024-3596",title:"CVE-2024-3596",description:"Lifecycle of CVE-2024-3596",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},l,d={},a=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function o(e){let t={a:"a",h2:"h2",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,n.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,r.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,r.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2024-3596",children:"CVE-2024-3596"})," to learn more."]}),"\n",(0,r.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,r.jsx)(t.p,{children:"11/06/2024"}),"\n",(0,r.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,r.jsx)(t.p,{children:"04/17/2026"}),"\n",(0,r.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,r.jsx)(t.p,{children:"krb5-libs"}),"\n",(0,r.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,r.jsx)(t.p,{children:"RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature."}),"\n",(0,r.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2024-3596",children:"9"})}),"\n",(0,r.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,r.jsx)(t.p,{children:"With this vulnerability, an attacker can forge RADIUS responses, effectively bypassing authentication controls and gaining unauthorized access to network resources. The containers where this is reported in has controls makes it very difficult to satisfy the preconditions for this security bug to be exploited. For ex: to conduct the man in the middle attacks with this vulnerability user has to get high\nprivilege acess to the containers and the underlying cluster where these are running. The impact of this bug for our product is low. Once the upstream fixes become available, we will adopt those."}),"\n",(0,r.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,r.jsx)(t.p,{children:"Ongoing"}),"\n",(0,r.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Version"}),(0,r.jsx)(t.th,{children:"Palette Enterprise"}),(0,r.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,r.jsx)(t.th,{children:"VerteX"}),(0,r.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.8.51"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.7.29"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.6.41"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.5.22"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.4.20"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]})]})]}),"\n",(0,r.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,r.jsx)(t.p,{children:"No revisions available."})]})}function h(e={}){let{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(o,{...e})}):o(e)}},884429:function(e,t,i){i.d(t,{R:()=>c,x:()=>l});var s=i(296540);let r={},n=s.createContext(r);function c(e){let t=s.useContext(n);return s.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function l(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:c(e.components),s.createElement(n.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.