CVE-2023-32649
DoS on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, allows an unauthenticated attacker to crash the IDS module by sending specially crafted malformed network packets.
During the (limited) time window before the IDS module is automatically restarted, network traffic may not be analyzed.
Vulnerabilidad de Denegación de Servicio (Dos) en Nozomi Networks Guardian y CMC, debido a una validación de entrada incorrecta en ciertos campos utilizados en la funcionalidad de inteligencia de activos de nuestro IDS, permite a un atacante no autenticado bloquear el módulo IDS enviando paquetes de red con formato incorrecto especialmente manipulado. Durante el período de tiempo (limitado) antes de que el módulo IDS se reinicie automáticamente, es posible que no se analice el tráfico de red.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-06-12 CVE Reserved
- 2023-09-19 CVE Published
- 2024-09-20 CVE Updated
- 2024-09-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-1286: Improper Validation of Syntactic Correctness of Input
CAPEC
- CAPEC-607: Obstruction
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.nozominetworks.com/NN-2023:10-01 | 2024-05-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nozominetworks Search vendor "Nozominetworks" | Cmc Search vendor "Nozominetworks" for product "Cmc" | >= 22.6.0 < 22.6.3 Search vendor "Nozominetworks" for product "Cmc" and version " >= 22.6.0 < 22.6.3" | - |
Affected
| ||||||
Nozominetworks Search vendor "Nozominetworks" | Cmc Search vendor "Nozominetworks" for product "Cmc" | >= 23.0.0 < 23.1.0 Search vendor "Nozominetworks" for product "Cmc" and version " >= 23.0.0 < 23.1.0" | - |
Affected
| ||||||
Nozominetworks Search vendor "Nozominetworks" | Guardian Search vendor "Nozominetworks" for product "Guardian" | >= 22.6.0 < 22.6.3 Search vendor "Nozominetworks" for product "Guardian" and version " >= 22.6.0 < 22.6.3" | - |
Affected
| ||||||
Nozominetworks Search vendor "Nozominetworks" | Guardian Search vendor "Nozominetworks" for product "Guardian" | >= 23.0.0 < 23.1.0 Search vendor "Nozominetworks" for product "Guardian" and version " >= 23.0.0 < 23.1.0" | - |
Affected
|