CVE-2024-24568Improper Access Control in Suricata

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 72.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDoisf/suricata7.0.07.0.3
Debianoisf/suricata< 1:7.0.3-1+1
CVEListV5oisf/suricata>= 7.0.0, < 7.0.3

Also affects: Fedora 38, 39

Patches

🔴Vulnerability Details

2
OSV
CVE-2024-24568: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine2024-02-26
CVEList
Suricata http2: header handling evasion2024-02-26

📋Vendor Advisories

1
Debian
CVE-2024-24568: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...2024
CVE-2024-24568 — Improper Access Control in Suricata | cvebase