Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65j3-gr82-45jh

Опубликовано: 09 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation.

In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation.

EPSS

Процентиль: 9%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-324

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation.

EPSS

Процентиль: 9%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-324