Security Advisory

CVE-2024-32384

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-01 00:00:00
Last updated 2025-12-01 16:13:32
Assigner mitre
CVSS score 6.8
State PUBLISHED

Description

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.