Helix Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Helix products.
Products
- Helix Core8 vulnerabilities
- Helix Swarm1 vulnerability
- Sync1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-10314HIGH | Unauthenticated Denial of Service via Auto Generation FunctionIn Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek. CWE-400Nov 11, 2024 | CVSS8.7v4.0 | EPSS0.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10344HIGH | Unauthenticated Denial of Service via Refuse FunctionIn Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek. CWE-400Nov 11, 2024 | CVSS8.7v4.0 | EPSS0.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10345HIGH | Unauthenticated Denial of Service via Shutdown FunctionIn Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek. CWE-400Nov 11, 2024 | CVSS8.7v4.0 | EPSS0.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8067MEDIUM | Unicode "best fit" argument injectionIn versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified. CWE-176Sep 24, 2024 | CVSS5.8v4.0 | EPSS0.199% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Command Injection in Helix SyncIn Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins. | CVSS3.6v3.1 | EPSS0.752% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-5759HIGH | Unauthenticated Remote Denial-of-Service via Buffer in Helix CoreIn Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner. CWE-400Nov 8, 2023 | CVSS7.5v3.1 | EPSS0.947% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-45319HIGH | Unauthenticated Remote Denial-of-Service (Commit) in Helix CoreIn Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner. CWE-400Nov 8, 2023 | CVSS7.5v3.1 | EPSS0.946% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-45849CRITICAL | Arbitrary Code Execution in Helix CoreAn arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner. CWE-94Nov 8, 2023 | CVSS9.0v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35767HIGH | Unauthenticated Remote Denial-of-Service via Shutdown Function in Helix CoreIn Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner. CWE-400Nov 8, 2023 | CVSS7.5v3.1 | EPSS0.947% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |