AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-28872

HIGH · CVSS 8.9 EPSS 0.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-07-11 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.9. It may lead to a denial-of-service condition.

CVE
CVE-2024-28872
Severity
HIGH
CVSS
8.9
EPSS
0.29%

Original NVD Description

The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the Stork agent. Once this connection is established with the valid certificate, the attacker can send malicious commands to a monitored service (Kea or BIND 9), possibly resulting in confidential data loss and/or denial of service. It should be noted that this vulnerability is not related to BIND 9 or Kea directly, and only customers using the Stork management tool are potentially affected. This issue affects Stork versions 0.15.0 through 1.15.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)