Skip to main content
EPSS 0.3%top 75%

CVE-2024-1488: Incorrect Default Permissions

0
High
VulnerabilityCVE-2024-1488cvecve-2024-1488
Published: 02/15/2024 (02/15/2024, 05:04:13 UTC)
Source: CVE Database V5

Description

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

CVSS v3.1

Score 8.0high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Affected software

redhat/unbound
pkg:rpm/redhat/unbound
Affected versions
=1.16.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 13:04:02 UTC

Technical Analysis

The vulnerability in Unbound (CVE-2024-1488) stems from incorrect default permissions that permit any process outside the unbound group to modify the runtime configuration if it can connect to localhost on port 8953. The default configuration with "control-use-cert: no" and IP-based "control-interface" allows improper access. An attacker with local access can manipulate the running Unbound instance, potentially changing forwarders to monitor DNS queries or disrupt DNS resolution. Red Hat advisories for RHEL 8 and 9 provide updated Unbound packages that mitigate this by introducing a new configuration file (/etc/unbound/conf.d/remote-control.conf) which sets "control-interface" to a Unix socket and enables "control-use-cert: yes" to restrict access. Verification can be done using "unbound-control status | grep control" to check if SSL or named pipe control is enabled, indicating a non-vulnerable configuration. The advisories recommend updating to the fixed packages and adjusting configuration files accordingly.

Potential Impact

An unprivileged local attacker can connect to the Unbound control interface on localhost port 8953 and modify the runtime configuration. This can lead to manipulation of DNS forwarders, enabling tracking of all queries forwarded by the local resolver, and potentially disrupting DNS resolution. The vulnerability allows unauthorized configuration changes, which can compromise confidentiality and integrity of DNS operations and availability of DNS resolution.

Mitigation Recommendations

Red Hat has released updated Unbound packages for RHEL 8 and 9 that address this vulnerability. The fix involves adding a new configuration file (/etc/unbound/conf.d/remote-control.conf) that restricts control access to a Unix socket and enables certificate-based authentication (control-use-cert: yes). Users should update to the patched versions provided by Red Hat advisories RHSA-2024:1750 and RHSA-2024:1751. To verify if a system is vulnerable, run "unbound-control status | grep control"; output containing "control(ssl)" or "control(namedpipe)" indicates a non-vulnerable configuration. If only "control" is returned, the system is vulnerable and should be fixed by including the new configuration file or adding the directives to custom control configuration files. Follow Red Hat's update instructions at https://access.redhat.com/articles/11258.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2024-02-14T12:47:25.283Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/errata/RHSA-2024:1750","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1751","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1780","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1801","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1802","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1804","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:2587","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:2696","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:0837","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2024-1488","vendor":"Red Hat"}]

Threat ID: 69135a44b36faa5b6c0e5fe3

Added to database: 11/11/2025, 15:46:12 UTC

Last enriched: 08/07/2026, 13:04:02 UTC

Last updated: 09/10/2026, 19:36:47 UTC

Views: 355

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses