PT-2024-5635 · Nginx · Nginx Plus

Published

2024-08-14

·

Updated

2024-09-06

·

CVE-2024-39792

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions NGINX Plus (affected versions not specified)
Description The issue is related to a memory exhaustion vulnerability in the NGINX Plus MQTT pre-read module. It can be exploited by undisclosed requests, leading to an increase in memory resource utilization. This can cause system instability, performance degradation, and potentially force manual restarts of NGINX processes. Approximately 624 devices may be affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-06334
CVE-2024-39792

Affected Products

Nginx Plus