CVE-2024-1410
CVSS 3.1 Score 3.7 of 10 (low)
Details
Summary
CVE-2024-1410 is a vulnerability affecting Cloudflare's quiche implementation, which could result in excessive resource consumption due to unbounded storage of connection ID retirement information. Each QUIC connection has a set of connection IDs, and endpoints declare the limit of active IDs they support using the active_connection_id_limit transport parameter. An unauthenticated remote attacker can exploit this vulnerability by manipulating the connection, sending NEW_CONNECTION_ID frames at a faster rate than RETIRE_CONNECTION_ID frames can be processed, leading to the storage of old connection IDs in an unbounded queue. Quiche versions 0.19.2 and 0.20.1 are the earliest to address this issue, and there is currently no workaround for affected versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.