CVE detail
CVE-2024-10394 — CVE-2024-10394
Published 2024-11-14 · Modified 2026-06-17 · Vendor openafs · Product openafs · Source nvd
HIGH
severity
CVSS-derived band
0.0020
EPSS probability
exploitation probability, 30d
10.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credentials in that PAG.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References