CVE-2023-46118Medium· 4.9▾ SunlitRabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
1.1%
1.1% → 1.1%
Responsibly disclosed by @NSEcho.
HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages.
An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism.
A PoC was provided to Team RabbitMQ privately.
Denial of Service
rabbit_common >= 3.12.0, < 3.12.7rabbit_common >= 3.11.0, < 3.11.24Upgrade to a patched release:
rabbit_common 3.12.7rabbit_common 3.11.24Connected by shared product, vendor, weakness, or advisory.
CVE-2022-31008Medium· 5.5RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
CVE-2020-3563High· 8.6A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device
CVE-2020-3554High· 7.5A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditi…
CVE-2020-3533High· 8.6A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly.…
CVE-2020-3529High· 8.6A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected de…
CVE-2020-3528High· 8.6A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected devi…