7.5
CVE-2024-4056
- EPSS 0.78%
- Veröffentlicht 26.04.2024 06:15:06
- Zuletzt bearbeitet 23.02.2026 11:16:17
- Quelle security@m-files.com
- CVE-Watchlists
- Unerledigt
Denial of service condition in M-Files Server
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
M-files ≫ M-files Server Version >= 23.11.13168.6 < 24.4.13592
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.78% | 0.509 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@m-files.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-1333 Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
https://product.m-files.com/security-advisories/cve-2024-4056/
https://www.m-files.com/about/trust-center/security-advisories/cve-2024-4056/
https://empower.m-files.com/security-advisories/CVE-2024-4056