VDB
CVE-2024-54677
CVE-2024-54677
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service due to lacking data upload limits
EPSS 1.94% · 79.4th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:H/RL:O/RC:C
EPSS Score
1.94%
79.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | B&R Industrial Automation GmbH APROL <R 4.4-01P5 |
Timeline
- Dec 17, 2024 CVE Published
- Dec 18, 2024 EPSS Score
- Feb 27, 2025 Coalition ESS Score
- Apr 18, 2025 EPSS Score
- Jul 1, 2025 EPSS Score
- Jul 1, 2025 Coalition ESS Score
- Jul 5, 2025 EPSS Score
- Jul 13, 2025 EPSS Score
- Jul 16, 2025 EPSS Score
- Jul 19, 2025 EPSS Score
- Jul 23, 2025 EPSS Score
- Aug 1, 2025 EPSS Score
References
- https://psirt.abb.com/csaf/2026/sa26p011.json advisory
- https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P011-661853b7.pdf advisory
- https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-54677 advisory