Processing Time of DAV User-Agents Now Monitored and Requests Terminated if Threshold Reached
CVE-2023-41705

6.5MEDIUM

Key Information:

Vendor
CVE Published:
12 February 2024

What is CVE-2023-41705?

The vulnerability arises from the improper processing of user-defined DAV user-agent strings, which, if exploited, can lead to a substantial processing load that may degrade the availability of the OX App Suite. As a protective measure, the product has been updated to monitor the processing time of these user-agents. If specific resource thresholds are breached, the related requests are automatically terminated to mitigate the impact. No publicly disclosed exploits exist for this vulnerability, but it is crucial for users to implement available updates and patch releases to ensure uninterrupted service.

Affected Version(s)

OX App Suite 0 <= 7.10.6-rev55

OX App Suite 0 <= 7.6.3-rev71

OX App Suite 0 <= 8.20

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.