Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37151


Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.


Published

2024-07-11T15:15:11.847

Last Modified

2024-11-21T09:23:18.420

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-754
  • Type: Primary
    CWE-754

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oisf suricata < 6.0.20 Yes
Application oisf suricata < 7.0.6 Yes

References