VulnerabilityAnalyzed
CVE-2024-8287
An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
HIGH 7.5EPSS 0.18%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.18% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- canonical/anbox cloud
- Source
- security@ubuntu.com
References
- https://bugs.launchpad.net/anbox-cloud/+bug/2077570Vendor Advisory
- https://discourse.ubuntu.com/t/anbox-cloud-1-23-1-has-been-released/48141Release Notes
- https://www.cve.org/CVERecord?id=CVE-2024-8287Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.