CVE-2024-37151Improper Check for Unusual or Exceptional Conditions in Suricata

Severity
7.5HIGHNVD
CNA5.3
EPSS
0.5%
top 34.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 11

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDoisf/suricata6.0.06.0.20+1
Debianoisf/suricata< 1:6.0.1-3+deb11u1+2
CVEListV5oisf/suricata>= 6.0.0, < 6.0.20, >= 7.0.0,< 7.0.6+1

Patches

🔴Vulnerability Details

2
CVEList
Suricata defrag: IP ID reuse can lead to policy bypass2024-07-11
OSV
CVE-2024-37151: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine2024-07-11

📋Vendor Advisories

1
Debian
CVE-2024-37151: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...2024
CVE-2024-37151 — Oisf Suricata vulnerability | cvebase