CVE-2024-28249 - CVE House
Back to Database
Status published Medium CVE-2024-28249

Cilium has possible unencrypted traffic between nodes when using IPsec and L7 policies

Vulnerability Description

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled and traffic matching Layer 7 policies, IPsec-eligible traffic between a node's Envoy proxy and pods on other nodes is sent unencrypted and IPsec-eligible traffic between a node's DNS proxy and pods on other nodes is sent unencrypted. This issue has been resolved in Cilium 1.15.2, 1.14.8, and 1.13.13. There is no known workaround for this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28249

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

cilium
Vulnerable Versions:
< 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2

Timeline

Official Publish: March 18th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses (CWE)