SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17596

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key.

HIGH 7.5EPSS 4.69%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
4.69% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-436
Affected
golang/go · debian/debian linux · fedoraproject/fedora · redhat/developer tools · redhat/enterprise linux · redhat/enterprise linux server · opensuse/leap · arista/cloudvision portal · arista/terminattr · arista/eos · arista/mos
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.