Unlimited Resource Accumulation in Modbus Traffic
CVE-2024-38534

7.5HIGH

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
11 July 2024

What is CVE-2024-38534?

Suricata, a widely-used network Intrusion Detection System and Network Security Monitoring engine, is impacted by a vulnerability that arises from crafted modbus traffic. This vulnerability can lead to unlimited resource accumulation within a single flow, potentially disrupting the functioning of the security engine. To mitigate this issue, it is advised to upgrade to version 7.0.6 and to set a limited value for the stream.reassembly.depth parameter, which helps in controlling the amount of unused resources. For further details and guidance, additional resources and advisories are available in the linked references.

Affected Version(s)

suricata < 7.0.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-38534 : Unlimited Resource Accumulation in Modbus Traffic