CVE-2024-2462
CVE-2024-2462 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-297.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.8)
- EPSS exploit prediction: 0% (13th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-27411
- Weakness: CWE-297
- Published:
- Last modified:
Description
Allow attackers to intercept or falsify data exchanges between the client and the server
Frequently asked questions
- What is CVE-2024-2462?
- Allow attackers to intercept or falsify data exchanges between the client and the server
- How severe is CVE-2024-2462?
- CVE-2024-2462 has a CVSS 4.0 base score of 6.8, rated medium severity.
- Is CVE-2024-2462 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (13th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2024-2462?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-2462 have an EU (EUVD) identifier?
- Yes. CVE-2024-2462 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-27411.
- When was CVE-2024-2462 published?
- CVE-2024-2462 was published on 2024-06-11 and last updated on 2026-06-17.
References
Other CWE-297 vulnerabilities
- CVE-2025-46408 — Critical (CVSS 9.8): An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and…
- CVE-2026-59638 — Critical (CVSS 9.3): In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.…
- CVE-2026-15925 — Critical (CVSS 9.2): Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have…
- CVE-2026-48144 — Critical (CVSS 9.1): Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue…
- CVE-2025-68637 — Critical (CVSS 9.1): The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default.…
- CVE-2026-35563 — High (CVSS 8.5): It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate…