Lucene search

K
cveAdobeCVE-2024-20716
HistoryFeb 15, 2024 - 2:15 p.m.

CVE-2024-20716

2024-02-1514:15:45
CWE-400
adobe
web.nvd.nist.gov
17
adobe commerce
cve-2024-20716
uncontrolled resource consumption
dos
vulnerability

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

AI Score

5

Confidence

High

EPSS

0.001

Percentile

26.9%

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to exhaust system resources, causing the application to slow down or crash. Exploitation of this issue does not require user interaction.

Affected configurations

Nvd
Vulners
Node
adobecommerceMatch2.4.4-
OR
adobecommerceMatch2.4.4p1
OR
adobecommerceMatch2.4.4p2
OR
adobecommerceMatch2.4.4p3
OR
adobecommerceMatch2.4.4p4
OR
adobecommerceMatch2.4.4p5
OR
adobecommerceMatch2.4.4p6
OR
adobecommerceMatch2.4.5-
OR
adobecommerceMatch2.4.5p1
OR
adobecommerceMatch2.4.5p2
OR
adobecommerceMatch2.4.5p3
OR
adobecommerceMatch2.4.5p4
OR
adobecommerceMatch2.4.5p5
OR
adobecommerceMatch2.4.6-
OR
adobecommerceMatch2.4.6p1
OR
adobecommerceMatch2.4.6p2
OR
adobecommerceMatch2.4.6p3
VendorProductVersionCPE
adobecommerce2.4.4cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*
adobecommerce2.4.4cpe:2.3:a:adobe:commerce:2.4.4:p1:*:*:*:*:*:*
adobecommerce2.4.4cpe:2.3:a:adobe:commerce:2.4.4:p2:*:*:*:*:*:*
adobecommerce2.4.4cpe:2.3:a:adobe:commerce:2.4.4:p3:*:*:*:*:*:*
adobecommerce2.4.4cpe:2.3:a:adobe:commerce:2.4.4:p4:*:*:*:*:*:*
adobecommerce2.4.4cpe:2.3:a:adobe:commerce:2.4.4:p5:*:*:*:*:*:*
adobecommerce2.4.4cpe:2.3:a:adobe:commerce:2.4.4:p6:*:*:*:*:*:*
adobecommerce2.4.5cpe:2.3:a:adobe:commerce:2.4.5:-:*:*:*:*:*:*
adobecommerce2.4.5cpe:2.3:a:adobe:commerce:2.4.5:p1:*:*:*:*:*:*
adobecommerce2.4.5cpe:2.3:a:adobe:commerce:2.4.5:p2:*:*:*:*:*:*
Rows per page:
1-10 of 171

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Adobe Commerce",
    "vendor": "Adobe",
    "versions": [
      {
        "lessThanOrEqual": "2.4.4-p6",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

AI Score

5

Confidence

High

EPSS

0.001

Percentile

26.9%

Related for CVE-2024-20716