VDB

CVE-2023-3341

CVE-2023-3341 PUBLISHED CVSS 7.5 HIGH

The vulnerability involves the recursive processing of control channel messages sent to named, which can exhaust stack memory and cause named to terminate unexpectedly. Exploiting this flaw requires only network access to the control channel's configured TCP port, without needing a valid RNDC key.

EPSS 0.25% · 48.2th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:W/RC:C
EPSS Score
0.25%
48.2th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3

Timeline

  • Sep 20, 2023 CVE Published
  • Sep 22, 2023 EPSS Score
  • Oct 24, 2023 EPSS Score
  • Dec 27, 2023 EPSS Score
  • Jan 28, 2024 EPSS Score
  • Mar 1, 2024 EPSS Score
  • May 4, 2024 EPSS Score
  • Jun 5, 2024 EPSS Score
  • Jul 7, 2024 EPSS Score
  • Sep 9, 2024 EPSS Score
  • Oct 11, 2024 EPSS Score
  • Nov 12, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›