« Volver al listado

CVE-2024-6156

Estado: AnalizadaBaja (3.8)—

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-6156",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6156",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-06T16:39:16.738252Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 3.8,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://github.com/canonical/lxd",
          "vendor": "Canonical Ltd.",
          "product": "LXD",
          "versions": [
            {
              "status": "affected",
              "version": "4.0",
              "lessThan": "4.0.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.0",
              "lessThan": "5.0.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.0",
              "lessThan": "5.21.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.0",
              "lessThan": "6.1",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "lxd",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*"
          ],
          "vendor": "canonical",
          "product": "lxd",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.21.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-12-06T00:15:04.380",
  "references": [
    {
      "url": "https://github.com/canonical/lxd/security/advisories/GHSA-4c49-9fpc-hc3v",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-6156",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store."
    },
    {
      "lang": "es",
      "value": "Mark Laing descubrió que el modo PKI de LXD, hasta la versión 5.21.2, podía eludirse si el certificado del cliente estaba presente en el almacén de confianza."
    }
  ],
  "lastModified": "2026-06-17T08:17:24.003",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39F8A2B1-F73D-4ADB-8E4D-E9D42D2ABB7B",
              "versionEndExcluding": "4.0.10",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E48F1136-C506-457C-B541-6290724B2070",
              "versionEndExcluding": "5.0.4",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF3D3966-CFB4-46B6-8BDA-BE54667A9482",
              "versionEndExcluding": "5.21.2",
              "versionStartIncluding": "5.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}