CVE-2024-1410

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Mar 12, 2024
Updated: Mar 13, 2024
CWE ID 400

Summary

CVE-2024-1410 is a vulnerability affecting Cloudflare's quiche implementation, which could result in excessive resource consumption due to unbounded storage of connection ID retirement information. Each QUIC connection has a set of connection IDs, and endpoints declare the limit of active IDs they support using the active_connection_id_limit transport parameter. An unauthenticated remote attacker can exploit this vulnerability by manipulating the connection, sending NEW_CONNECTION_ID frames at a faster rate than RETIRE_CONNECTION_ID frames can be processed, leading to the storage of old connection IDs in an unbounded queue. Quiche versions 0.19.2 and 0.20.1 are the earliest to address this issue, and there is currently no workaround for affected versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share