Lucene search

K
cveMitreCVE-2023-29487
HistoryDec 21, 2023 - 1:15 a.m.

CVE-2023-29487

2023-12-2101:15:32
CWE-1333
mitre
web.nvd.nist.gov
31
cve-2023
heimdal
thor agent
dos
threat prevention
windows
macos

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.001

Percentile

17.8%

An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is not a valid vulnerability. Their DNS Security for Endpoint solution includes an optional feature to provide extra information on the originating process that made a DNS request. The lack of process identification in DNS logs is therefore falsely categorized as a DoS issue.

Affected configurations

Nvd
Node
heimdalsecuritythorRange3.5.3
AND
microsoftwindowsMatch-
Node
heimdalsecuritythorRange2.6.9
AND
applemacosMatch-
VendorProductVersionCPE
heimdalsecuritythor*cpe:2.3:a:heimdalsecurity:thor:*:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
applemacos-cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.001

Percentile

17.8%

Related for CVE-2023-29487