CVE-2024-45796 Information
Nov 01, 2024
cve
Description
Suricata is a network Intrusion Detection System Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7 a logic error during fragment reassembly can lead to failed reassembly for valid traffic. An attacker could craft packets to trigger this behavior.This issue has been addressed in 7.0.7.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Reference
https://github.com/OISF/suricata/security/advisories/GHSA-mf6r-3xp2-v7xg https://redmine.openinfosecfoundation.org/issues/7067
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
5.3
Share on: