CVE-2024-29971
Scontain Scone 5.8.0 … 5.9.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.
Summary
CVE-2024-29971 is a critical-severity an unspecified weakness vulnerability in Scontain Scone. Its CVSS base score is 9.8 (Critical).
Operationally, ranked at the 38th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2024-29971 is an interface vulnerability in Scontain SCONE version 5.8.0 that leads to state corruption via injected signals. The vulnerability affects the SCONE software component developed by Scontain, with the CVE published on 2025-01-10. It is classified under CWE-Other and carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), marking it as critical severity.
Remote attackers require no privileges or user interaction to exploit this vulnerability over the network with low complexity. By injecting signals, attackers can corrupt the internal state of SCONE instances, resulting in high impacts to confidentiality, integrity, and availability.
Mitigation details and further information are available in the referenced advisories, including a proof-of-concept at https://github.com/ahoi-attacks/sigy/blob/main/pocs/scone/cve.md and the vendor site at https://scontain.com.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-26945
Vulnerability Data
Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.