Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-2466


libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).


Published

2024-03-27T08:15:41.343

Last Modified

2025-07-30T19:42:21.037

Status

Analyzed

Source

2499f714-1537-4658-8207-48ae4bb9eae9

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-297

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application haxx curl < 8.7.0 Yes
Operating System apple macos < 12.7.6 Yes
Operating System apple macos < 13.6.8 Yes
Operating System apple macos < 14.6 Yes
Operating System netapp h700s_firmware - Yes
Hardware netapp h700s - No
Operating System netapp bootstrap_os - Yes
Hardware netapp hci_compute_node - No
Operating System netapp h300s_firmware - Yes
Hardware netapp h300s - No
Operating System netapp h410s_firmware - Yes
Hardware netapp h410s - No
Operating System netapp h500s_firmware - Yes
Hardware netapp h500s - No

References