SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-23759

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely.

HIGH 7.5EPSS 0.72%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.72% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-617
Affected
facebook/fizz
Source
cve-assign@fb.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.