SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2024-2758

Tempesta FW rate limits are not enabled by default.

MEDIUM 6.3EPSS 72.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 72.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Tempesta FW rate limits are not enabled by default. They are either set too large to capture empty CONTINUATION frames attacks or too small to handle normal HTTP requests appropriately.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS
72.75% probability · 99th percentile
CISA KEV
Not listed
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.