6.5
CVE-2024-52917
- EPSS 0.27%
- Veröffentlicht 18.11.2024 04:15:04
- Zuletzt bearbeitet 30.04.2025 16:16:39
- CVE-Watchlists
- Unerledigt
Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitcoin ≫ Bitcoin Core Version < 22.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.181 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures
https://bitcoincore.org/en/2024/07/31/disclose-upnp-oom/