CVE-2024-21194

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Oct 15, 2024
Updated: Mar 13, 2025
CWE ID 400

Summary

CVE-2024-21194 is a vulnerability affecting Oracle MySQL's InnoDB component in versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. This easily exploitable issue enables high privileged attackers with network access, through multiple protocols, to cause a denial-of-service (DoS) attack on MySQL Server. Successful exploitation may result in a hang or frequent crashes of the server, leading to significant availability disruptions. The Base Score of this vulnerability, as per CVSS 3.1, is 4.9. Attack vectors include network access, with a high privilege level required. No user interaction is necessary.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share