CVE-2024-55629

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 6, 2025
CWE ID 437

Summary

CVE-2024-55629 affects Suricata, a widely-used network Intrusion Detection System and Intrusion Prevention System. Prior to version 7.0.8, Suricata may analyze out-of-band TCP data differently than applications at the endpoints, potentially allowing evasions. This vulnerability can be mitigated by configuring Suricata to handle TCP urgent data differently, such as dropping all packets with the urgent flag set in IPS mode. Users are urged to update to version 7.0.8 or implement the recommended configuration changes to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share