CVE-2023-22092
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Summary
CVE-2023-22092 is a newly identified vulnerability affecting Oracle MySQL Server versions 8.0.34 and prior. This issue resides in the Optimizer component and can be exploited by a high-privileged attacker with network access. Vulnerabilities of this type allow attackers to cause a hang or frequently repeatable crash of MySQL Server, resulting in a Denial of Service (DoS) situation. The base score of this vulnerability, according to the Common Vulnerability Scoring System (CVSS), is 4.9. The vector for attack is network (AV:N), with a low complexity (AC:L), high privileges required for exploitation (PR:H), and no user interaction needed (UI:N). The impact of this vulnerability is primarily on the availability (S:U) of the affected MySQL Server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- MySQL
Affected Vendors
- BonqDAO