cbcvebase.
CVE-2024-24568
published 2024-02-26

CVE-2024-24568: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting…

PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.64%
46.0th percentile
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiansuricata< suricata 1:7.0.3-1 (forky)suricata 1:7.0.3-1 (forky)
fedoraprojectfedora
fedoraprojectfedora
oisfsuricata
oisfsuricata>= 0 < 1:7.0.3-11:7.0.3-1
oisfsuricata>= 0 < 1:7.0.3-11:7.0.3-1
oisfsuricata>= 7.0.0 < 7.0.37.0.3

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.