VulnerabilityModified
CVE-2003-1433
Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.
MEDIUM 4.3EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- epic games/unreal engine
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html
- http://www.pivx.com/luigi/adv/ueng-adv.txt
- http://www.securityfocus.com/bid/6771
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11304
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html
- http://www.pivx.com/luigi/adv/ueng-adv.txt
- http://www.securityfocus.com/bid/6771
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11304
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.