CVE-2020-26164: Medium severity kde connect vulnerability
In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-26164?
CVE-2020-26164 is a vulnerability in kdeconnect-kde (aka KDE Connect) before 20.08.2 that allows an attacker on the local network to send crafted packets that trigger a Denial of Service attack.
What is the severity of CVE-2020-26164?
The severity of CVE-2020-26164 is medium, with a severity value of 5.5.
How can an attacker exploit CVE-2020-26164?
An attacker can exploit CVE-2020-26164 by sending crafted packets on the local network to trigger a Denial of Service attack.
Which software versions are affected by CVE-2020-26164?
Versions of kdeconnect-kde (aka KDE Connect) before 20.08.2 are affected by CVE-2020-26164.
How can I mitigate CVE-2020-26164?
To mitigate CVE-2020-26164, it is recommended to update to version 20.08.2 or later of kdeconnect-kde (aka KDE Connect).