VulnerabilityDeferred
CVE-2024-2758
Tempesta FW rate limits are not enabled by default.
MEDIUM 6.3EPSS 72.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 72.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Tempesta FW rate limits are not enabled by default. They are either set too large to capture empty CONTINUATION frames attacks or too small to handle normal HTTP requests appropriately.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 72.75% probability · 99th percentile
- CISA KEV
- Not listed
- Source
- cret@cert.org
References
- http://www.openwall.com/lists/oss-security/2024/04/03/16
- https://github.com/tempesta-tech/tempesta/security/advisories/GHSA-3xwj-5ch3-q9p4
- https://www.kb.cert.org/vuls/id/421644
- http://www.openwall.com/lists/oss-security/2024/04/03/16
- https://github.com/tempesta-tech/tempesta/security/advisories/GHSA-3xwj-5ch3-q9p4
- https://www.kb.cert.org/vuls/id/421644
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.