CVE-2024-45289
The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option.
Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1557Adversary-in-the-Middlecredential access · collection70 %
Acceso red sin privilegios (AV:N, PR:N, UI:N) → T1190. Impacto: confidencialidad alta permite eavesdropping (T1557) al ignorar revocación de certificados, exponiendo sesiones HTTPS a MITM.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-665
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-45289",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-45289",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-13T14:22:38.085444Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secteam@freebsd.org",
"affectedData": [
{
"vendor": "FreeBSD",
"modules": [
"bhyve"
],
"product": "FreeBSD",
"versions": [
{
"status": "affected",
"version": "14.1-RELEASE",
"lessThan": "p6",
"versionType": "release"
},
{
"status": "affected",
"version": "13.4-RELEASE",
"lessThan": "p2",
"versionType": "release"
},
{
"status": "affected",
"version": "13.3-RELEASE",
"lessThan": "p8",
"versionType": "release"
}
],
"defaultStatus": "unknown"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:freebsd:freebsd:-:*:*:*:*:*:*:*"
],
"vendor": "freebsd",
"product": "freebsd",
"versions": [
{
"status": "affected",
"version": "14.1-release",
"lessThan": "p6",
"versionType": "custom"
},
{
"status": "affected",
"version": "13.4-release",
"lessThan": "p2",
"versionType": "custom"
},
{
"status": "affected",
"version": "13.3-release",
"lessThan": "p8",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-11-12T15:15:10.070",
"references": [
{
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:18.ctl.asc",
"source": "secteam@freebsd.org"
},
{
"url": "https://security.netapp.com/advisory/ntap-20250110-0001/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secteam@freebsd.org",
"description": [
{
"lang": "en",
"value": "CWE-665"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option.\n\nFetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option."
},
{
"lang": "es",
"value": "La librería fetch(3) utiliza variables de entorno para pasar cierta información, incluida la ruta del archivo de revocación. El nombre de la variable de entorno que utiliza fetch(1) para pasar el nombre del archivo a la librería era incorrecto, por lo que, en efecto, se ignoraba la opción. Fetch seguiría conectándose a un host que presente un certificado incluido en el archivo de revocación que se pasa a la opción --crl."
}
],
"lastModified": "2026-06-17T07:53:57.517",
"sourceIdentifier": "secteam@freebsd.org"
}