CVE-2024-46304
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 9, 2024
Updated: Oct 10, 2024
CWE ID 120
Summary
CVE-2024-46304 is a newly disclosed vulnerability affecting libcoap version 4.3.5-rc2 and older. This issue involves a NULL pointer dereference, which can be exploited by remote attackers. They can trigger this vulnerability by making a malicious request to the coap_handle_request_put_block function located in src/coap_block.c. The exploitation of this vulnerability results in a denial of service. System administrators are strongly advised to update their libcoap installations to a patched version in order to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.