We found results for “”
CVE-2023-49275
Date: April 19, 2024
Wazuh is a free and open source platform used for threat prevention, detection, and response. A NULL pointer dereference was detected during fuzzing of the analysis engine, allowing malicious clients to DoS the analysis engine. The bug occurs when "analysisd" receives a syscollector message with the "hotfix" "msg_type" but lacking a "timestamp". It uses "cJSON_GetObjectItem()" to get the "timestamp" object item and dereferences it without checking for a "NULL" value. A malicious client can DoS the analysis engine. This vulnerability is fixed in 4.7.1.
Language: C
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
NULL Pointer Dereference
CWE-476CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


