7.5

CVE-2024-11738

Exploit

Rustls: rustls network-reachable panic in `acceptor::accept`

A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rustls Project ≫ Rustls Version 0.23.13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.71% 0.489
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RedHat 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-248 Uncaught Exception

An exception is thrown from a function, but it is not caught.

https://access.redhat.com/security/cve/CVE-2024-11738
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2328732
Vendor Advisory
https://github.com/advisories/GHSA-qg5g-gv98-5ffh
Third Party Advisory
https://github.com/rustls/rustls
Product
https://github.com/rustls/rustls/issues/2227
Vendor Advisory
Exploit
Issue Tracking
https://rustsec.org/advisories/RUSTSEC-2024-0399.html
Vendor Advisory