CVE-2024-55628
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 6, 2025
CWE ID 779
CWE ID 405
Summary
CVE-2024-55628 affects Suricata, a popular network Intrusion Detection System and Security Monitoring engine. The vulnerability stems from an issue with DNS resource name compression, which allows small DNS messages to contain unusually large hostnames. These oversized hostnames, though restricted, can result in costly decoding processes and expansive DNS log records. Fortunately, this issue has been resolved in Suricata version 7.0.8.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.