PT-2022-7087 · Unknown · Qubes-Mirage-Firewall

Burghardt

·

Published

2022-07-12

·

Updated

2023-08-08

·

CVE-2022-46770

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions qubes-mirage-firewall versions 0.8.x through 0.8.3
Description The issue is related to a denial of service caused by a crafted multicast UDP packet. This can lead to CPU consumption and loss of forwarding. The vulnerability can be exploited by sending specially crafted UDP packets to an IP address range of 224.0.0.0 through 239.255.255.255.
Recommendations For versions 0.8.x through 0.8.3, consider restricting access to the vulnerable qubes-mirage-firewall to minimize the risk of exploitation. As a temporary workaround, avoid using the IP address range of 224.0.0.0 through 239.255.255.255 in the affected environment until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2023-07548
CVE-2022-46770
OSEC-2022-01

Affected Products

Qubes-Mirage-Firewall