TCP Urgent Data Handling Vulnerability in Suricata by Open Information Security Foundation
CVE-2024-55629

7.5HIGH

What is CVE-2024-55629?

The vulnerability in Suricata arises from the improper handling of TCP urgent data in versions prior to 7.0.8. This oversight can cause the Suricata engine to interpret TCP streams inconsistently compared to the applications at the TCP endpoints, potentially leading to evasion of security measures. The 7.0.8 update introduces configurable options for managing TCP urgent data more effectively. Users are advised to implement rules in IPS mode, such as dropping packets with the urgent flag set, to mitigate this risk.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.