PT-2024-21427 · Vseeface · Vseeface

Published

2024-03-26

·

Updated

2024-08-05

·

CVE-2024-26577

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions VSeeFace versions 1.13.38.c2 and earlier
Description The issue allows attackers to cause a denial of service, resulting in an application hang, via a spoofed UDP packet containing at least 10 digits in JSON data.
Recommendations For versions 1.13.38.c2 and earlier, as a temporary workaround, consider restricting the handling of UDP packets with JSON data containing at least 10 digits to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-26577

Affected Products

Vseeface