cbcvebase.
CVE-2024-1488
published 2024-02-15

CVE-2024-1488: A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime…

PriorityP341high7.3CVSS 3.1
AVLACLPRLUINSUCLIHAH
EPSS
0.32%
23.9th percentile
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
debianunbound
fedoraprojectunbound< 1.19.1-2.fc401.19.1-2.fc40
redhatcodeready_linux_builder
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus_for_power_little_endian
redhatcodeready_linux_builder_eus_for_power_little_endian
redhatcodeready_linux_builder_for_arm64
redhatcodeready_linux_builder_for_arm64
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_arm_64_eus

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
vendor_debian8.0LOW
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.