SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-21671

This could aid attackers in credential attacks.

LOW 3.7EPSS 0.40%

Does this matter?

Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.

Description

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks. Version 4.2.0 patches this vulnerability.

CVSS 3.1
3.7 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.40% probability · 34th percentile
CISA KEV
Not listed
Weakness
CWE-208, CWE-203
Affected
vantage6/vantage6
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.