CVE-2019-25076
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache, aka a Tuple Space Explosion (TSE) attack.
El algoritmo TSS (Tuple Space Search) en Open vSwitch versiones 2.x hasta 2.17.2 y 3.0.0, permite a atacantes remotos causar una denegación de servicio (retrasos del tráfico legítimo) por medio de datos de paquetes diseñados que requieren un tiempo de evaluación excesivo dentro del algoritmo de clasificación de paquetes para la caché de MegaFlow, también se conoce como ataque Tuple Space Explosion (TSE)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-08 CVE Reserved
- 2022-09-08 CVE Published
- 2024-03-31 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://arxiv.org/abs/2011.09107 | Third Party Advisory | |
https://dl.acm.org/citation.cfm?doid=3359989.3365431 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://sites.google.com/view/tuple-space-explosion | 2024-08-05 | |
https://www.youtube.com/watch?v=5cHpzVK0D28 | 2024-08-05 | |
https://www.youtube.com/watch?v=DSC3m-Bww64 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openvswitch Search vendor "Openvswitch" | Openvswitch Search vendor "Openvswitch" for product "Openvswitch" | >= 2.0.0 <= 2.17.2 Search vendor "Openvswitch" for product "Openvswitch" and version " >= 2.0.0 <= 2.17.2" | - |
Affected
| ||||||
Openvswitch Search vendor "Openvswitch" | Openvswitch Search vendor "Openvswitch" for product "Openvswitch" | 3.0.0 Search vendor "Openvswitch" for product "Openvswitch" and version "3.0.0" | - |
Affected
|