Wazuh
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*
- >= 3.9.0
A denial-of-service vulnerability has been identified in Wazuh versions 3.9.0 and above, prior to 4.14.5. The issue allows remote attackers to cause memory exhaustion in the cluster protocol parser by sending a crafted message header with an excessively large payload length. This length is trusted before authentication or decryption, and is used directly to allocate memory, resulting in an unauthenticated denial-of-service condition for the cluster service.
Exploitation of this vulnerability leads to uncontrolled memory allocation, causing process memory growth and service instability. The Wazuh cluster daemon can degrade or crash as a result.
The vulnerability can be reproduced by sending a crafted message header to the Wazuh manager's cluster port (default 1516) with an oversized payload length. This can be done using a Python script that creates a socket connection to the manager's IP and port, and sends the crafted header repeatedly. If the cluster SSL is enabled, the connection should be wrapped with an SSL context that disables hostname verification and certificate validation.
Users can upgrade to Wazuh version 4.14.5 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.