Описание
In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation.
Ссылки
- Issue Tracking
- Patch
- Not Applicable
- Issue Tracking
- Patch
- Not Applicable
Уязвимые конфигурации
Конфигурация 1Версия до 2023-10-30 (исключая)
cpe:2.3:a:pquic:pquic:*:*:*:*:*:*:*:*
EPSS
Процентиль: 9%
0.00031
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-324
Связанные уязвимости
CVSS3: 6.5
github
почти 2 года назад
In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation.
EPSS
Процентиль: 9%
0.00031
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-324