CVE-2024-6237
moderate-risk
Published 2024-07-09
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
Do I need to act?
-
0.82% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10
Medium
NETWORK
/ LOW complexity
Affected Products (3)
Affected Vendors
References (8)
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2024-6237
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2293579
Issue Tracking
https://github.com/389ds/389-ds-base/issues/5989
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2024-6237
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2293579
Issue Tracking
https://github.com/389ds/389-ds-base/issues/5989
36
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
3/34 · Minimal
Exposure
9/34 · Low