CVE-2024-4227

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 15, 2025
CWE ID 416

Summary

CVE-2024-4227 is a vulnerability affecting Genivia gSOAP. With a specific XML configuration having duplicate ID attributes, an unauthenticated attacker can trigger a high CPU load, resulting in a Denial of Service (DoS) condition. This issue occurs due to the gSOAP parser's failure to handle duplicate ID attributes efficiently. Attackers can force the parser to process such XML files repeatedly, causing significant resource consumption and potential downtime for affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share