CVE-2024-45692: High severity virtualmin vulnerability
Published Sep 4, 2024
·Updated
Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.
Affected Software
2 affected components
Virtualmin Virtualmin<7.20.2
webmin webmin<2.202
Event History
Sep 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-45692?
CVE-2024-45692 has a severity level that can allow for significant service disruption through network traffic loops.
2
How do I fix CVE-2024-45692?
To fix CVE-2024-45692, upgrade Webmin to version 2.202 or later and Virtualmin to version 7.20.2 or later.
3
What software versions are affected by CVE-2024-45692?
CVE-2024-45692 affects Webmin versions earlier than 2.202 and Virtualmin versions earlier than 7.20.2.
4
What type of attack does CVE-2024-45692 enable?
CVE-2024-45692 enables a denial of service attack through a network traffic loop via spoofed UDP packets.
5
Is CVE-2024-45692 related to any specific network services?
CVE-2024-45692 specifically affects services running on port 10000, which is used by Webmin and Virtualmin.