Sploitus

CVE-2024-49214

No indexed exploits for CVE-2024-49214 yet

QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.

Affected products
Debian, Haproxy, Red Os
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
0.5% (41th percentile)
Weakness
CWE-290
NVD status
Deferred
Published
2024-10-14
CVE-2024-49214 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-49214 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-49214 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.