A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
CVE ID: CVE-2024-7383
CVSS Base Severity: HIGH
CVSS Base Score: 7.4
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor: , Red Hat
Product: , Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 Advanced Virtualization
EPSS Score: 0.13% (probability of being exploited)
EPSS Percentile: 33.59% (scored less or equal to compared to others)
EPSS Date: 2025-06-15 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: total
SSVC Automatable: false