NULL Pointer Dereference in Wazuh Analysis Engine
CVE-2023-49275

6.5MEDIUM

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
19 April 2024

What is CVE-2023-49275?

A vulnerability has been identified in the Wazuh analysis engine, where a NULL pointer dereference can occur due to a missing timestamp in a syscollector message. This situation can be exploited by malicious clients, leading to a Denial of Service (DoS) condition within the analysis engine. The issue arises specifically when analysisd attempts to access a timestamp object without validating its existence, resulting in instability. This vulnerability has been addressed in version 4.7.1 of the Wazuh platform.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.