Unauthenticated Denial of Service via Refuse Function
CVE-2024-10344

8.7HIGH

Key Information:

Vendor

Helix

Vendor
CVE Published:
11 November 2024

What is CVE-2024-10344?

A security flaw exists in Helix Core prior to version 2024.2, enabling unauthenticated remote attackers to exploit the refuse function and trigger a denial of service. This vulnerability poses a significant risk as it can disrupt operations by making the service unavailable to legitimate users. Organizations utilizing this software should review their current version and consider upgrading to mitigate risk. Reported by security researcher Karol Wiśek, this vulnerability highlights the need for vigilance in maintaining updated software and robust cybersecurity practices.

Affected Version(s)

Helix Core 0.0.0 < 2024.2

Helix Core 0.0.0 < 2024.1

Helix Core 0.0.0 < 2023.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.
CVE-2024-10344 : Unauthenticated Denial of Service via Refuse Function