CVE-2024-28870
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community. When parsing an overly long SSH banner, Suricata can use excessive CPU resources, as well as cause excessive logging volume in alert records. This issue has been patched in versions 6.0.17 and 7.0.4.
- Oisf Suricata
- < 6.0.17, 7.0.4
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.6% (45th percentile)
- Weakness
- CWE-770
- NVD status
- Analyzed
- Published
- 2024-04-03
CVE-2024-28870 at NVD
No indexed exploits for CVE-2024-28870 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-28870 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.