PT-2022-17186 · Unknown · Sflow Decode Package

Justin Timperio

·

Published

2022-09-30

·

Updated

2024-08-21

·

CVE-2022-2529

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions sflow decode package versions prior to 3.4.4
Description The issue is related to insufficient packet sanitization in the sflow decode package, which can lead to a denial of service attack. Attackers can craft malformed packets, causing the process to consume large amounts of memory and resulting in a denial of service.
Recommendations For versions prior to 3.4.4, update to version 3.4.4 to resolve the issue. As a temporary workaround, consider restricting public access to the goflow collector to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-2529
GHSA-9RPW-2H95-666C
GO-2022-1032

Affected Products

Sflow Decode Package