7.5
CVE-2024-0316
- EPSS 0.05%
- Veröffentlicht 15.01.2024 16:15:13
- Zuletzt bearbeitet 21.11.2024 08:46:18
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the containment_notify/preview parameter, which could lead to a service outage.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fireeye ≫ Endpoint Security Version5.2.0.958244
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.161 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| cve-coordination@incibe.es | 6.8 | 2.5 | 4.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
|
CWE-460 Improper Cleanup on Thrown Exception
The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.