Aller au contenu

Fiche vulnérabilité

CVE-2024-32038 : faille critique wazuh wazuh (CVSS 9.8)

Description

Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow hazard in wazuh-analysisd when handling Unicode characters from Windows Eventchannel messages. It impacts Wazuh Manager 3.8.0 and above. This vulnerability is fixed in Wazuh Manager 4.7.2.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
19 avr. 2024
Dernière mise à jour
2 août 2024

Produits concernés

  • wazuh wazuh

Références

Rechercher une autre vulnérabilité dans la base CVE