CVE-2024-33070

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 7, 2024
Updated: Oct 16, 2024
CWE ID 125
CWE ID 126

Summary

CVE-2024-33070 refers to a transient Denial of Service (DoS) vulnerability discovered in the parsing of ESP IE from beacon or probe response frames. An attacker can exploit this vulnerability by sending specially crafted packets to the affected system, causing it to crash or become unresponsive for a brief period of time. This issue could potentially impact network availability and performance, necessitating prompt mitigation efforts. The exact cause of the vulnerability lies within the parsing logic for ESP IE frames, and further investigation is ongoing to determine potential exploit vectors and potential impacts beyond DoS.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share