CVE-2024-24990
published 2024-02-14CVE-2024-24990: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.91%
56.1th percentile
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 1.26.0-1 (forky) | nginx 1.26.0-1 (forky) |
| f5 | nginx | >= 0 < 1.26.0-1 | 1.26.0-1 |
| f5 | nginx | >= 0 < 1.26.0-1 | 1.26.0-1 |
| f5 | nginx_open_source | — | — |
| f5 | nginx_open_source | >= 1.25.0 < 1.25.4 | 1.25.4 |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R30 < R30 P2 | R30 P2 |
| f5 | nginx_plus | >= R31 < R31 P1 | R31 P1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-24990: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate
osv·2024-02-14·CVSS 7.5
CVE-2024-24990 [HIGH] CVE-2024-24990: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
GHSA
GHSA-38gr-cjjp-3f5w: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate
ghsa_unreviewed·2024-02-14
CVE-2024-24990 [HIGH] CWE-416 GHSA-38gr-cjjp-3f5w: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CISA ICS
Siemens SINEC Traffic Analyzer
cisa_ics·2025-08-14·CVSS 7.5
[HIGH] Siemens SINEC Traffic Analyzer
ICS Advisory
##
Siemens SINEC Traffic Analyzer
Release DateAugust 14, 2025
Alert CodeICSA-25-226-17
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC Traffic Analyzer
- Vulnerabilities: NULL Pointer Dereference, Use After Free, Uncontrolled Resource Consumption, Execution
F5
CVE-2024-24990: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worke...
vendor_f5·2024-02-14·CVSS 7.5
CVE-2024-24990 [HIGH] CWE-416 CVE-2024-24990: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worke...
CVE-2024-24990: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worke...
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products: NGINX Plus, Nginx Open Source
Affected Versions: 1.25.0 - 1.25.4; r30; r31
F5 Advisory Articles: K000138445
F5 References: https://my.f5.com/manage/s/article/K000138445
Red Hat
nginx: Use-after-free in HTTP/3
vendor_redhat·2024-02-14·CVSS 7.5
CVE-2024-24990 [HIGH] CWE-416 nginx: Use-after-free in HTTP/3
nginx: Use-after-free in HTTP/3
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
A flaw was found in the nginx HTTP/3 implementation. This issue may allow an attacker to use a specially crafted QUIC session to trigger a use-after-free condition, causing a worker process to crash, leading to a denial of service.
Statement: The nginx package as shipped in Red Hat Enterprise Linux 8, 9 and RHSCL is not affected by this vulner
Debian
CVE-2024-24990: nginx - When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undis...
vendor_debian·2024·CVSS 7.5
CVE-2024-24990 [HIGH] CVE-2024-24990: nginx - When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undis...
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.26.0-1)
sid: resolved (fixed in 1.26.0-1)
trixie: resolved (fixed in 1.26.0-1)
Suricata
ET EXPLOIT TerraMaster TOS Information Leak Inbound (CVE-2022-24990)
suricata·2022-03-29·CVSS 7.5
CVE-2022-24990 [HIGH] ET EXPLOIT TerraMaster TOS Information Leak Inbound (CVE-2022-24990)
ET EXPLOIT TerraMaster TOS Information Leak Inbound (CVE-2022-24990)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT TerraMaster TOS Information Leak Inbound (CVE-2022-24990)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/module/api.php?mobile/webNasIPS"; fast_pattern; reference:cve,2022-24990; classtype:attempted-recon; sid:2035631; rev:2; metadata:attack_target Server, created_at 2022_03_29, cve CVE_2022_24990, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
No public exploits indexed.
No writeups or analysis indexed.
2024-02-14
Published