CVE-2024-3979: COVESA vsomeip race condition
Published Apr 19, 2024
·Updated
A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this issue is some unknown functionality. The manipulation leads to race condition. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261596.
Affected Software
1 affected component
COVESA vsomeip<=3.4.10
Event History
Apr 19, 2024
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3979?
CVE-2024-3979 has been classified as problematic due to a race condition vulnerability.
2
What versions of COVESA vsomeip are affected by CVE-2024-3979?
CVE-2024-3979 affects COVESA vsomeip versions up to and including 3.4.10.
3
How do I fix CVE-2024-3979?
To mitigate CVE-2024-3979, updating COVESA vsomeip to a version beyond 3.4.10 is recommended.
4
What type of attack is associated with CVE-2024-3979?
CVE-2024-3979 is associated with local attacks exploiting a race condition.
5
Is there an exploit publicly available for CVE-2024-3979?
Yes, the exploit for CVE-2024-3979 has been disclosed to the public.