CVE-2024-51774 - Overview, Insights & Trends

CVE-2024-51774

Published Nov 2, 2024

Last updated 5 months ago

CVSS high 8.1
qBittorrent

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2024-51774 is a security vulnerability found in qBittorrent versions prior to 5.0.1. The vulnerability stems from the application proceeding to use HTTPS URLs even after encountering certificate validation errors. This issue existed for a significant period, from April 6, 2010, until it was patched on October 12, 2024. The flaw lies within the DownloadManager class, where SSL certificate validation errors were ignored. Exploitation of this vulnerability could lead to man-in-the-middle (MITM) attacks and remote code execution (RCE), especially on Windows systems where malicious files could be downloaded and executed under the guise of legitimate updates.

Description
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
Source
cve@mitre.org
NVD status
Modified

Insights

Analysis from the Intruder Security Team
Published Nov 5, 2024

Exploiting this vulnerability requires the attacker to execute a Man-in-the-Middle (MITM) attack, which is unlikely to be exploitable against the average user.

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-295
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-295

Social media

Hype score
Not currently trending

Configurations