First published: Mon Jul 23 2018(Updated: )
An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Suricata-ids Suricata | <3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10728 is a vulnerability in Suricata IDS that can lead to missed detection if an ICMPv4 error packet is received as the first packet on a flow in the to_client direction.
The severity of CVE-2016-10728 is medium, with a severity value of 5.3.
CVE-2016-10728 affects Suricata IDS versions up to and including 3.1.2.
CVE-2016-10728 can be exploited by sending an ICMPv4 error packet as the first packet on a flow in the to_client direction, which confuses the rule grouping lookup logic in Suricata IDS.
Yes, upgrading to Suricata IDS version 3.1.3 or later fixes CVE-2016-10728.