PT-2024-19106 · Unknown · Hacker Hotel Badge 2024

Casper Kuijpers

+3

·

Published

2024-02-11

·

Updated

2024-10-16

·

CVE-2024-21875

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Hacker Hotel Badge 2024 versions 0.1.0 through 0.1.3
Description The issue is related to an Allocation of Resources Without Limits or Throttling vulnerability in the Badge, leading to a denial of service attack. This vulnerability allows flooding on the Hacker Hotel Badge 2024, specifically on risc-v billboard modules.
Recommendations For versions 0.1.0 through 0.1.3, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the billboard modules to minimize the risk of exploitation. Avoid using the vulnerable badge until the issue is resolved.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-21875

Affected Products

Hacker Hotel Badge 2024