CVE-2024-30170: SSH Privx

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, and in major version 34.0 and later,

Affected products

  • SSH Privx: from 22.0, before 31.3 (fixed in 31.3); from 32.0, before 32.3 (fixed in 32.3); version 33.0 only

Published 2024-08-06. Last modified 2026-06-17.