// For flags

CVE-2023-41706

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing of user-defined drive search expressions is not limited No publicly available exploits are known.

Ahora se supervisa el tiempo de procesamiento de las expresiones de búsqueda de unidades y la solicitud relacionada finaliza si se alcanza un umbral de recursos. La disponibilidad de OX App Suite podría verse reducida debido a la alta carga de procesamiento. Implemente las actualizaciones y lanzamientos de parches proporcionados. El procesamiento de expresiones de búsqueda de unidades definidas por el usuario no está limitado. No se conocen exploits disponibles públicamente.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-08-30 CVE Reserved
  • 2024-02-12 CVE Published
  • 2024-02-17 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Open-Xchange GmbH
Search vendor "Open-Xchange GmbH"
OX App Suite
Search vendor "Open-Xchange GmbH" for product "OX App Suite"
<= 7.10.6-rev55
Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 7.10.6-rev55"
en
Affected
Open-Xchange GmbH
Search vendor "Open-Xchange GmbH"
OX App Suite
Search vendor "Open-Xchange GmbH" for product "OX App Suite"
<= 7.6.3-rev71
Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 7.6.3-rev71"
en
Affected
Open-Xchange GmbH
Search vendor "Open-Xchange GmbH"
OX App Suite
Search vendor "Open-Xchange GmbH" for product "OX App Suite"
<= 8.19
Search vendor "Open-Xchange GmbH" for product "OX App Suite" and version " <= 8.19"
en
Affected