Cyber Posture

CVE-2024-37566

Critical

Published: 27 February 2025

Published
27 February 2025
Modified
10 April 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0027 50.6th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.

Security Summary

CVE-2024-37566 is an improper authentication vulnerability (CWE-284) in Infoblox NIOS through version 8.6.4, specifically affecting Grid functionality. Published on 2025-02-27, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity due to its potential for complete system compromise.

Unauthenticated attackers with network access can exploit this vulnerability with low attack complexity and no user interaction required. Successful exploitation enables high-impact outcomes, including unauthorized access leading to confidentiality breaches, integrity modifications, and availability disruptions on affected NIOS Grid deployments.

Infoblox has published mitigation guidance in their support article at https://support.infoblox.com/s/article/000010392. Security practitioners should consult this advisory for patching instructions and workarounds applicable to NIOS versions through 8.6.4.

Details

CWE(s)
CWE-284

Affected Products

infoblox
nios
8.6.0 — 8.6.4

References