Like many of you, I woke up yesterday to a CVE-2024-56346 security bulletin with a CVSS score of 10.
However, I find the provided information somewhat lacking-just a tar file with a README and some eFixes. There isn't much detail about the underlying issue or its full impact.
One thing that stands out to me: the simplest mitigation-"Stop the Nimesis server on a Nim server if you don't need it and stop the nimsh service on the client"-is oddly missing from the bulletin.
Is this enough to mitigate the issue until the patch can be installed?
------------------------------
Stefan Coussens
------------------------------