« Volver al listado

CVE-2024-34161

Estado: AnalizadaMedia (5.3)—

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-34161",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-34161",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-29T18:37:24.017204Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "F5",
          "modules": [
            "HTTP/3"
          ],
          "product": "NGINX Open Source",
          "versions": [
            {
              "status": "affected",
              "version": "1.25.0",
              "lessThan": "1.26.1",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "F5",
          "modules": [
            "HTTP/3"
          ],
          "product": "NGINX Plus",
          "versions": [
            {
              "status": "affected",
              "version": "R30",
              "lessThan": "R32",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:*"
          ],
          "vendor": "f5",
          "product": "nginx_plus",
          "versions": [
            {
              "status": "affected",
              "version": "r30",
              "versionType": "custom",
              "lessThanOrEqual": "r31"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:f5:nginx:1.25.0:*:*:*:*:*:*:*"
          ],
          "vendor": "f5",
          "product": "nginx",
          "versions": [
            {
              "status": "affected",
              "version": "1.25.0",
              "versionType": "custom",
              "lessThanOrEqual": "1.26.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-29T16:15:10.270",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/05/30/4",
      "tags": [
        "Mailing List"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLAOKJWDALQZBIV3WKGPJ6T5Z56D3PRD/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7RPLWC35WHEUFCGKNFG62ESNID25TEZ/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://my.f5.com/manage/s/article/K000139627",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/05/30/4",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLAOKJWDALQZBIV3WKGPJ6T5Z56D3PRD/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7RPLWC35WHEUFCGKNFG62ESNID25TEZ/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://my.f5.com/manage/s/article/K000139627",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f5sirt@f5.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory."
    },
    {
      "lang": "es",
      "value": "Cuando NGINX Plus o NGINX OSS están configurados para usar el módulo HTTP/3 QUIC y la infraestructura de red admite una unidad de transmisión máxima (MTU) de 4096 o más sin fragmentación, los paquetes QUIC no revelados pueden hacer que los procesos de trabajo de NGINX pierdan memoria previamente liberada."
    }
  ],
  "lastModified": "2026-06-17T07:33:01.003",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA79B55D-E494-4961-81C6-80363BE46FE0",
              "versionEndExcluding": "1.26.1",
              "versionStartIncluding": "1.25.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96BF2B19-52C7-4051-BA58-CAE6F912B72F"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r30:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EBEC829-7EED-487E-974D-BBA704DFBF0A"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r30:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0648596-D1F5-4A7A-B7F8-104E3AF26317"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8248517E-D805-4928-8252-2168472341EF"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r31:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D5BB4C0-B862-4CDD-AA54-1BC1BDF27005"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA277A6C-83EC-4536-9125-97B84C4FAF59"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}