SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-1488

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration.

HIGH 7.3EPSS 0.32%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

CVSS 3.1
7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Weakness
CWE-276
Affected
fedoraproject/unbound · redhat/codeready linux builder · redhat/codeready linux builder eus · redhat/codeready linux builder eus for power little endian · redhat/codeready linux builder for arm64 · redhat/codeready linux builder for arm64 eus · redhat/codeready linux builder for ibm z systems · redhat/codeready linux builder for ibm z systems eus · redhat/enterprise linux · redhat/enterprise linux eus · redhat/enterprise linux for arm 64 · redhat/enterprise linux for arm 64 eus · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux server aus · redhat/enterprise linux server for power little endian update services for sap solutions · redhat/enterprise linux server tus
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.