CVE-2022-24976
published 2022-02-14CVE-2022-24976: Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a…
PriorityP358critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.82%
76.5th percentile
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atheme | atheme | >= 7.2.0 < 7.2.12 | 7.2.12 |
| debian | atheme-services | < atheme-services 7.2.12-1 (bookworm) | atheme-services 7.2.12-1 (bookworm) |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-24976: atheme-services - Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allow...
vendor_debian·2022·CVSS 9.1
CVE-2022-24976 [CRITICAL] CVE-2022-24976: atheme-services - Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allow...
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
Scope: local
bookworm: resolved (fixed in 7.2.12-1)
bullseye: open
forky: resolved (fixed in 7.2.12-1)
sid: resolved (fixed in 7.2.12-1)
trixie: resolved (fixed in 7.2.12-1)
GHSA
GHSA-3fv4-6wvg-x83x: Atheme IRC Services before 7
ghsa_unreviewed·2022-02-15
CVE-2022-24976 [CRITICAL] CWE-287 GHSA-3fv4-6wvg-x83x: Atheme IRC Services before 7
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
OSV
CVE-2022-24976: Atheme IRC Services before 7
osv·2022-02-14·CVSS 9.1
CVE-2022-24976 [CRITICAL] CVE-2022-24976: Atheme IRC Services before 7
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/atheme/atheme/commit/4e664c75d0b280a052eb8b5e81aa41944e593c52https://github.com/atheme/atheme/compare/v7.2.11...v7.2.12https://www.openwall.com/lists/oss-security/2022/01/30/4https://github.com/atheme/atheme/commit/4e664c75d0b280a052eb8b5e81aa41944e593c52https://github.com/atheme/atheme/compare/v7.2.11...v7.2.12https://www.openwall.com/lists/oss-security/2022/01/30/4
2022-02-14
Published