CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Breaking the Chain: Wiz Uncovers a Signature Verification Bypass in Nuclei, the Popular Vulnerability Scanner (CVE-2024-43405)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1509

As cited

Copy frozen at (site build).

vulnerabilities

Breaking the Chain: Wiz Uncovers a Signature Verification Bypass in Nuclei, the Popular Vulnerability Scanner (CVE-2024-43405)

Wiz researchers discovered a high-severity vulnerability in Nuclei, a widely-used open-source vulnerability scanner, that allows bypassing signature verification and could enable arbitrary code execution. The flaw, tracked as CVE-2024-43405, affects a tool commonly relied upon by security teams for scanning and testing.

Why it matters: Security practitioners using Nuclei for vulnerability scanning face potential code execution risk if they run untrusted or modified scanner templates; immediate patching is critical to maintain the integrity of your scanning infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Breaking the Chain: Wiz Uncovers a Signature Verification Bypass in Nuclei, the Popular Vulnerability Scanner (CVE-2024-43405)

Wiz researchers discovered a high-severity vulnerability in Nuclei, a widely-used open-source vulnerability scanner, that allows bypassing signature verification and could enable arbitrary code execution. The flaw, tracked as CVE-2024-43405, affects a tool commonly relied upon by security teams for scanning and testing.

Why it matters: Security practitioners using Nuclei for vulnerability scanning face potential code execution risk if they run untrusted or modified scanner templates; immediate patching is critical to maintain the integrity of your scanning infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary