CVE-2023-5324

MEDIUM

Eeroos < 6.16.4-11 - Improper Resource Release

Title source: rule
STIX 2.1

Description

A vulnerability has been found in eeroOS up to 6.16.4-11 and classified as critical. This vulnerability affects unknown code of the component Ethernet Interface. The manipulation leads to denial of service. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241024.

Exploits (1)

nomisec WORKING POC 1 stars
by nomis · poc
https://github.com/nomis/eero-zero-length-ipv6-options-header-dos

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.241024
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.241024

Scores

CVSS v3 4.3
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
eero/eeroos < 6.16.4-11
Published Oct 01, 2023
Tracked Since Feb 18, 2026