CVE-2023-48949
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 29, 2023
Updated: Nov 30, 2023
Summary
CVE-2023-48949 is a Denial of Service vulnerability affecting the box_add function in openlink virtuoso-opensource version 7.2.11. By executing a specific SELECT statement, malicious actors can trigger the vulnerability, resulting in the system becoming unresponsive and unavailable to users. This issue represents a threat to the availability and integrity of applications using this version of openlink virtuoso-opensource and necessitates immediate patching or mitigation efforts to prevent potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share