PT-2024-7006 · Suricata+2 · Suricata+2

Published

2024-09-23

·

Updated

2025-11-07

·

CVE-2024-47522

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 7.0.7
Description The issue is related to errors in checking the JA4 identifier, which provides information about the application protocol to be used between the client and server. Exploitation of this issue can allow a remote attacker to cause a denial of service by sending specially crafted TLS/QUIC traffic. The problem is associated with the operation of the ja4 fingerprinting engine.
Recommendations For versions prior to 7.0.7, update to version 7.0.7 to resolve the issue. As a temporary workaround, consider disabling ja4 by setting app-layer.protocols.tls.ja3,4-fingerprints to no in the suricata.yaml configuration file.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14099
BDU:2024-08255
CVE-2024-47522
GHSA-W5XV-6586-JPM7
OPENSUSE-SU-2025:15394-1

Affected Products

Alt Linux
Debian
Suricata