First published: Thu Jul 11 2024(Updated: )
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within a flow. Upgrade to 7.0.6. Set a limited stream.reassembly.depth to reduce the issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OISF Suricata | <7.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38534 has a high severity level due to the potential for unlimited resource accumulation.
To fix CVE-2024-38534, upgrade Suricata to version 7.0.6 and set a limited stream.reassembly.depth.
CVE-2024-38534 affects Suricata versions prior to 7.0.6.
CVE-2024-38534 is a resource exhaustion vulnerability in Suricata.
Using an older version of Suricata with CVE-2024-38534 is not recommended due to the identified vulnerability.