CVE-2023-30575
Last modified
CVE-2023-30575 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through specially-crafted data. . EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through specially-crafted data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Guacamole | < 1.5.2 |
References
- https://lists.apache.org/thread/tn63n2lon0h5p45oft834t1dqvvxownvMailing List, Third Party Advisory
- https://lists.apache.org/thread/tn63n2lon0h5p45oft834t1dqvvxownvMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30575?
How severe is CVE-2023-30575?
How do I fix CVE-2023-30575?
Are you affected by CVE-2023-30575?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
