CVE-2023-38285

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jul 26, 2023
Updated: Aug 2, 2023
CWE ID 407

Summary

CVE-2023-38285 is a vulnerability affecting Trustwave ModSecurity 3.x versions prior to 3.0.10. This issue involves an inefficient algorithmic complexity, which can lead to significant performance degradation and potentially enable denial-of-service (DoS) attacks. An attacker can exploit this vulnerability by crafting specially crafted input that triggers the inefficient algorithm, causing excessive resource consumption and potential server crashes. The consequences can result in service disruptions and increased operational costs. It is recommended that users update to the latest version of ModSecurity to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Trustwave ModSecurity

Affected Vendors

  • Trustwave Holdings