CVE Vulnerabilities

CVE-2024-32388

Transmission of Private Resources into a New Sphere ('Resource Leak')

Published: Dec 01, 2025 | Modified: Dec 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the firewall and access UDP-based services that would otherwise be protected.

Weakness

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

Affected Software

Name Vendor Start Version End Version
Keros Kerlink 5.0 (including) 5.12 (excluding)

References