PT-2024-13938 · Unknown · Simple-Dhcp-Server

Published

2024-04-29

·

Updated

2024-11-01

·

CVE-2023-50433

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions simple-dhcp-server versions through ec976d2
Description The issue allows remote attackers to cause a denial of service by sending a malicious DHCP packet. This is caused by a type confusion bug that results in a large memory allocation. When the memory allocation fails, the DHCP server crashes.
Recommendations For simple-dhcp-server versions through ec976d2, as a temporary workaround, consider restricting access to the DHCP server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Type Confusion

Weakness Enumeration

Related Identifiers

CVE-2023-50433

Affected Products

Simple-Dhcp-Server