Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10363

Опубликовано: 16 июн. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:*
Версия до 2.3.2 (включая)

EPSS

Процентиль: 69%
0.00598
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-248
CWE-404

Связанные уязвимости

CVSS3: 7.5
debian
больше 8 лет назад

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, ...

CVSS3: 7.5
github
больше 3 лет назад

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.

EPSS

Процентиль: 69%
0.00598
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-248
CWE-404