CVE-2024-38534: Suricata modbus: txs without responses are never freed
Published Jul 11, 2024
·Updated
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within a flow. Upgrade to 7.0.6. Set a limited stream.reassembly.depth to reduce the issue.
Affected Software
1 affected component
OISF Suricata<7.0.6
Remediation
Event History
Jul 11, 2024
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38534?
CVE-2024-38534 has a high severity level due to the potential for unlimited resource accumulation.
2
How do I fix CVE-2024-38534?
To fix CVE-2024-38534, upgrade Suricata to version 7.0.6 and set a limited stream.reassembly.depth.
3
What software is affected by CVE-2024-38534?
CVE-2024-38534 affects Suricata versions prior to 7.0.6.
4
What type of vulnerability is CVE-2024-38534?
CVE-2024-38534 is a resource exhaustion vulnerability in Suricata.
5
Can I use an older version of Suricata with CVE-2024-38534?
Using an older version of Suricata with CVE-2024-38534 is not recommended due to the identified vulnerability.