CVE-2024-37151

MEDIUM

Suricata 6.0.0-6.0.19 - Policy Bypass via Fragmented Packet Reassembly Failure

Title source: llm
STIX 2.1

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.

Scores

CVSS v3 5.3
EPSS 0.0062
EPSS Percentile 44.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (1)
oisf/suricata 6.0.0 - 6.0.20
Published Jul 11, 2024
Tracked Since Feb 18, 2026