OISF Suricata
cpe:2.3:a:openinfosecfoundation:suricata:*:*:*:*:*:*:*
- < 7.0.15
A performance degradation vulnerability has been identified in Suricata, a network IDS, IPS, and NSM engine, prior to version 7.0.15. The issue arises from an inefficiency in DCERPC buffering, which can cause a significant processing cost and reduce the application's availability.
Exploitation of this vulnerability causes high processing costs, leading to a notable reduction in the application's availability.
Users can upgrade to Suricata version 7.0.15 or 8 to address this vulnerability. Alternatively, the 'dcerpc' parser can be disabled as a temporary workaround.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.