openwall.com
http://www.openwall.com/lists/oss-security/2024/09/04/1 CVE-2024-2169
HIGH
Implementations of UDP application protocols are susceptible to network loops and denial of service
Record summary
CVE-2024-2169 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC.
Description
Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | * | affected |
| Through * | affected | ||
RouterOS-TFTPBrowse MikroTik / RouterOS-TFTPDefault status: unknown | CVE List | * to ≤ 7.13.2 | affected |
| Through 7.13.2 | affected | ||
dproxy-nexgenBrowse dproxy-nexgen / dproxy-nexgen | CVE List | 0.1 to ≤ 0.5 | affected |
dproxy-nexgenBrowse dproxy-nexgen_project / dproxy-nexgenDefault status: unknown | CVE List | 0.1 to ≤ 0.5 | affected |
Proofs of concept
1Repository PoCs
GitHubrenancesarr/G3-Loop-DoSRepository PoCby renancesarrStars: 0Not analyzed3 files
References
4kb.cert.org
https://kb.cert.org/vuls/id/417980 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-2169 kb.cert.org
https://www.kb.cert.org/vuls/id/417980