Cyber Resilience

CVE-2024-29971

Scontain Scone 5.8.0 … 5.9.0

Published
10 January 2025
Modified
29 October 2025
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0046 38th percentile
Risk Priority 71 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2024-29971 is a critical-severity an unspecified weakness vulnerability in Scontain Scone. Its CVSS base score is 9.8 (Critical).

Operationally, ranked at the 38th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2024-29971 is an interface vulnerability in Scontain SCONE version 5.8.0 that leads to state corruption via injected signals. The vulnerability affects the SCONE software component developed by Scontain, with the CVE published on 2025-01-10. It is classified under CWE-Other and carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), marking it as critical severity.

Remote attackers require no privileges or user interaction to exploit this vulnerability over the network with low complexity. By injecting signals, attackers can corrupt the internal state of SCONE instances, resulting in high impacts to confidentiality, integrity, and availability.

Mitigation details and further information are available in the referenced advisories, including a proof-of-concept at https://github.com/ahoi-attacks/sigy/blob/main/pocs/scone/cve.md and the vendor site at https://scontain.com.

EU & UK References

Vulnerability Data

Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-38023Same product: Scontain Scone

Affected Assets

scontain
scone
5.8.0, 5.9.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References