CVE-2024-28870
Last modified
CVE-2024-28870 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community. When parsing an overly long SSH banner, Suricata can use excessive CPU resources, as well as cause excessive logging volume in alert records. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community. When parsing an overly long SSH banner, Suricata can use excessive CPU resources, as well as cause excessive logging volume in alert records. This issue has been patched in versions 6.0.17 and 7.0.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oisf | Suricata | < 6.0.17 |
| Oisf | Suricata | >= 7.0.0, < 7.0.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-28870?
How severe is CVE-2024-28870?
How do I fix CVE-2024-28870?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-28865django-wiki is a wiki system for Django. Installations of dj…7.5
- CVE-2024-28866GoCD is a continuous delivery server. GoCD versions from 19.…6.1
- CVE-2024-28867Swift Prometheus is a Swift client for the Prometheus monito…7.4
- CVE-2024-28868Umbraco is an ASP.NET content management system. Umbraco 10 …5.3
- CVE-2024-28869Traefik is an HTTP reverse proxy and load balancer. In affec…7.5
- CVE-2024-2887Type Confusion in WebAssembly in Google Chrome prior to 123.…7.7
- CVE-2024-28871LibHTP is a security-aware parser for the HTTP protocol and …7.5
- CVE-2024-28872The TLS certificate validation code is flawed. An attacker c…8.1
- CVE-2024-28875A security flaw involving hard-coded credentials in LevelOne…8.1
- CVE-2024-28876Uncontrolled search path for some Intel(R) MPI Library softw…7.3
- CVE-2024-28877MicroDicom DICOM Viewer is vulnerable to a stack-based buffe…8.8
- CVE-2024-28878 IO-1020 Micro ELD downloads source code or an executable fr…9.6
Are you affected by CVE-2024-28870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
