seclists.org
http://seclists.org/fulldisclosure/2024/Jun/4 CVE-2024-5422
HIGH
Denial of Service
Record summary
CVE-2024-5422 has a selected CVSS score of 7.1 (high).
Description
An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 20.1.22 | affected |
utnserver ProBrowse SEH Computertechnik / utnserver ProDefault status: unaffected | CVE List | Through 20.1.22 | affected |
utnserver ProMAXBrowse SEH Computertechnik / utnserver ProMAXDefault status: unaffected | CVE List | Through 20.1.22 | affected |
inu-100Browse seh / inu-100Default status: unknown | CVE List | Through 20.1.22 | affected |
utnserver_proBrowse seh / utnserver_proDefault status: unknown | CVE List | Through 20.1.22 | affected |
utnserver_promaxBrowse seh / utnserver_promaxDefault status: unknown | CVE List | Through 20.1.22 | affected |
References
3cyberdanube.com
https://cyberdanube.com/en/en-multiple-vulnerabilities-in-seh-untserver-pro/index.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-5422