Lucene search

K
redosRedosROS-20240613-01
HistoryJun 13, 2024 - 12:00 a.m.

ROS-20240613-01

2024-06-1300:00:00
redos.red-soft.ru
5
vulnerability
tls
manipulation
pad_len
disclosure
sensitive information
network boot
unix

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

19.4%

A vulnerability in the tls_new_ciphertext() function of the iPXE network boot standard is related to manipulation of the
pad_len argument in the src/net/tls.c file of the TLS component. Exploitation of the vulnerability could allow
an attacker acting remotely to disclose sensitive information

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64ipxe-roms< 20240119-1.gitde8a0821UNKNOWN

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

19.4%