Denial of Service Vulnerability in Aim Version 3.19.3
CVE-2024-6227

7.5HIGH

Key Information:

Vendor

aimhubio

Status
Vendor
CVE Published:
8 July 2024

What is CVE-2024-6227?

A vulnerability exists in Aimhubio software version 3.19.3, wherein an attacker can exploit the configuration of the remote tracking server to point to itself. This misconfiguration triggers an infinite loop, causing the server to continuously connect to itself, which prevents it from responding to any other incoming connections. This issue can lead to significant interruptions in server operations, thereby affecting the overall functionality of the systems relying on Aimhubio software.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.