« Volver al listado

CVE-2024-7010

Estado: ModificadaMedia (5.9)—

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-7010",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-7010",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-29T13:18:36.382204Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@huntr.dev",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@huntr.dev",
      "affectedData": [
        {
          "vendor": "mudler",
          "product": "mudler/localai",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.21",
              "versionType": "custom"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:mudler:localai:*:*:*:*:*:*:*:*"
          ],
          "vendor": "mudler",
          "product": "localai",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.21",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-29T13:15:08.683",
  "references": [
    {
      "url": "https://github.com/mudler/localai/commit/db1159b6511e8fa09e594f9db0fec6ab4e142468",
      "tags": [
        "Patch"
      ],
      "source": "security@huntr.dev"
    },
    {
      "url": "https://huntr.com/bounties/e286ed00-6383-47de-b5bc-9b9fad67c362",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "security@huntr.dev"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@huntr.dev",
      "description": [
        {
          "lang": "en",
          "value": "CWE-208"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-203"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the context of password handling, an attacker can determine valid login credentials based on the server's response time, potentially leading to unauthorized access."
    },
    {
      "lang": "es",
      "value": " La versión 2.17.1 de mudler/localai es vulnerable a un ataque de sincronización. Este tipo de ataque de canal lateral permite a un atacante comprometer el sistema criptográfico analizando el tiempo que lleva ejecutar algoritmos criptográficos. Específicamente, en el contexto del manejo de contraseñas, un atacante puede determinar credenciales de inicio de sesión válidas en función del tiempo de respuesta del servidor, lo que puede provocar un acceso no autorizado."
    }
  ],
  "lastModified": "2026-06-17T08:19:10.910",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mudler:localai:2.17.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDCAF2D5-46FD-4D8E-B65B-9BE9FDD5D686"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@huntr.dev"
}