CVE-2024-2511
Last modified
CVE-2024-2511 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. EPSS estimates a 54.03% chance of exploitation in the next 30 days.
Description
Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is also not affected by this issue.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-2511?
How severe is CVE-2024-2511?
How do I fix CVE-2024-2511?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25102This vulnerability exists in AppSamvid software due to the u…7.8
- CVE-2024-25103This vulnerability exists in AppSamvid software due to the u…6.3
- CVE-2024-25106OpenObserve is a observability platform built specifically f…6.5
- CVE-2024-25107WikiDiscover is an extension designed for use with a CreateW…6.1
- CVE-2024-25108Pixelfed is an open source photo sharing platform. When proc…8.8
- CVE-2024-25109ManageWiki is a MediaWiki extension allowing users to manage…5.4
- CVE-2024-25110The UAMQP is a general purpose C library for AMQP 1.0. Durin…8.1
- CVE-2024-25111Squid is a web proxy cache. Starting in version 3.5.27 and p…7.5
- CVE-2024-25112Exiv2 is a command-line utility and C++ library for reading,…5
- CVE-2024-25113Rejected reason: This CVE was misassigned. See CVE-2023-4762…
- CVE-2024-25114Collabora Online is a collaborative online office suite base…5.3
- CVE-2024-25115RedisBloom adds a set of probabilistic data structures to Re…7
Are you affected by CVE-2024-2511?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
