{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-6284","assignerOrgId":"14ed7db2-1595-443d-9d34-6215bf890778","state":"PUBLISHED","assignerShortName":"Google","dateReserved":"2024-06-24T13:16:59.140Z","datePublished":"2024-07-03T22:58:17.340Z","dateUpdated":"2025-09-08T09:36:50.396Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"https://github.com/google/nftables","repo":"https://github.com/google/nftables","vendor":"Google","versions":[{"status":"affected","version":"0.1.0"},{"status":"unaffected","version":"0.2.0"}]}],"datePublic":"2024-05-13T04:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>In <a target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/google/nftables\">https://github.com/google/nftables</a>&nbsp;IP addresses were encoded in the wrong byte order,&nbsp;resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses).<br><br>This issue affects:&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://pkg.go.dev/github.com/google/nftables@v0.1.0\">https://pkg.go.dev/github.com/google/nftables@v0.1.0</a><br><br>The bug was fixed in the next released version:&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://pkg.go.dev/github.com/google/nftables@v0.2.0\">https://pkg.go.dev/github.com/google/nftables@v0.2.0</a></p>"}],"value":"In  https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses).\n\nThis issue affects:  https://pkg.go.dev/github.com/google/nftables@v0.1.0 \n\nThe bug was fixed in the next released version:  https://pkg.go.dev/github.com/google/nftables@v0.2.0"}],"impacts":[{"capecId":"CAPEC-180","descriptions":[{"lang":"en","value":"CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1286","description":"CWE-1286 Improper Validation of Syntactic Correctness of Input","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-1389","description":"CWE-1389 Incorrect Parsing of Numbers with Different Radices","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"14ed7db2-1595-443d-9d34-6215bf890778","shortName":"Google","dateUpdated":"2025-09-08T09:36:50.396Z"},"references":[{"url":"https://github.com/google/nftables/issues/225"},{"url":"https://github.com/crowdsecurity/cs-firewall-bouncer/issues/368"},{"url":"https://bugs.launchpad.net/ubuntu/+source/crowdsec-firewall-bouncer/+bug/2069596"}],"source":{"discovery":"UNKNOWN"},"title":"Improper IPv4 and IPv6 byte order storage in github.com/google/nftables","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:33:05.456Z"},"title":"CVE Program Container","references":[{"url":"https://github.com/google/nftables/issues/225","tags":["x_transferred"]},{"url":"https://github.com/crowdsecurity/cs-firewall-bouncer/issues/368","tags":["x_transferred"]},{"url":"https://bugs.launchpad.net/ubuntu/+source/crowdsec-firewall-bouncer/+bug/2069596","tags":["x_transferred"]}]},{"affected":[{"vendor":"netfilter","product":"nftables","cpes":["cpe:2.3:a:netfilter:nftables:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"0.1.0","status":"affected","lessThan":"0.2.0","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-08-19T14:56:05.757333Z","id":"CVE-2024-6284","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-08-19T14:58:42.867Z"}}]}}