Cloudflare quiche
cpe:2.3:a:cloudflare:quiche:*:*:*:*:*:*:*
- < 0.24.4
A vulnerability in Cloudflare Quiche versions prior to 0.24.4 allows for incorrect growth of the congestion window. This flaw can lead to data being sent faster than the actual capacity of the network path. An unauthenticated remote attacker can exploit this by completing a handshake and starting a congestion-controlled data transfer. The attacker can then manipulate the victim's congestion control state by sending ACK frames, taking advantage of an opportunistic ACK attack as described in RFC 9000 Section 21.4. This manipulation can cause the victim to exceed normal congestion window limits, allowing more bytes in flight than the path can reliably support.
Exploitation of this vulnerability can disrupt normal data transmission rates, causing potential congestion and inefficiencies in network communication.
Users can upgrade to Cloudflare Quiche version 0.24.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.