AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-1488

HIGH · CVSS 8 EPSS 0.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-02-15 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.0. See the original NVD description below for full technical details.

CVE
CVE-2024-1488
Severity
HIGH
CVSS
8
EPSS
0.32%

Original NVD Description

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

Related CVEs

Other vulnerabilities affecting the same vendor(s)