CVE-2009-2299 describes a denial-of-service vulnerability affecting specific versions of the Artofdefence Hyperguard Web Application Firewall (WAF) module for Apache HTTP Server. Remote attackers can exploit this by sending an HTTP request with a large Content-Length header but no actual POST data, leading to excessive memory consumption on the affected server. This vulnerability has a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network with low attack complexity and requires no authentication, but its impact is limited to availability (denial of service). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are extremely low, suggesting it has received minimal attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.5-11635CPE matchmatch criteria | cpe:2.3:a:hyperguard_web_application_firewall_project:hyperguard_web_application_firewall:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.0.3-11636CPE matchmatch criteria | cpe:2.3:a:hyperguard_web_application_firewall_project:hyperguard_web_application_firewall:*:*:*:*:*:*:*:* | ||
>= 3.1, < 3.1.1-11637CPE matchmatch criteria | cpe:2.3:a:hyperguard_web_application_firewall_project:hyperguard_web_application_firewall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.