CVE-2024-57646
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 14, 2025
Updated: Jan 15, 2025
CWE ID 89
Summary
CVE-2024-57646 is a newly identified vulnerability affecting the psiginfo component in openlink virtuoso-opensource version 7.2.11. This issue permits attackers to initiate a Denial of Service (DoS) attack via specifically crafted SQL statements. The vulnerability arises due to an unhandled condition within the component, providing malicious actors an opportunity to cause service interruption. To mitigate this risk, users are encouraged to upgrade to the latest version of openlink virtuoso-opensource or apply relevant patches as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Virtuoso-Opensource
Affected Vendors
- OpenLink Software Inc