CVE-2022-24976Improper Authentication in Atheme

Severity
9.1CRITICALNVD
EPSS
0.1%
top 68.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateFeb 15

Description

Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

debiandebian/atheme-services< atheme-services 7.2.12-1 (bookworm)
NVDatheme/atheme7.2.07.2.12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3fv4-6wvg-x83x: Atheme IRC Services before 72022-02-15
OSV
CVE-2022-24976: Atheme IRC Services before 72022-02-14

📋Vendor Advisories

1
Debian
CVE-2022-24976: atheme-services - Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allow...2022
CVE-2022-24976 — Improper Authentication in Atheme | cvebase