CVE-2023-33297

HIGH EXPLOITED IN THE WILD

Bitcoin Core < 24.1 - Denial of Service via Inventory Queue Drain Inefficiency

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-33297 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.

Scores

CVSS v3 7.5
EPSS 0.0140
EPSS Percentile 69.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2023-05-22
InTheWild.io 2023-05-22
CWE
CWE-400
Status published
Products (1)
bitcoin/bitcoin_core < 24.1
Published May 22, 2023
Tracked Since Feb 18, 2026