PT-2024-14011 · Quic · Quic

Published

2024-02-20

·

Updated

2024-12-04

·

CVE-2023-50923

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions QUIC in RFC 9000 (affected versions not specified)
Description The Latency Spin Bit specification in QUIC does not strictly constrain the bit value when the feature is disabled. This might allow remote attackers to construct a covert channel with data represented as changes to the bit value. According to a research paper, modern internet communication protocols provide numerous ways to hide or embed data within normal network traffic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-50923

Affected Products

Quic