A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email addresses) when in possession of the audit events database.
References
Configurations
No configuration.
History
15 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email addresses) when in possession of the audit events database. | |
| References |
|
06 Aug 2024, 19:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-321 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| Summary |
|
01 Aug 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-08-01 16:15
Updated : 2025-12-15 17:15
NVD link : CVE-2024-41260
Mitre link : CVE-2024-41260
CVE.ORG link : CVE-2024-41260
JSON object : View
Products Affected
No product.
CWE
CWE-321
Use of Hard-coded Cryptographic Key
