CVE-2019-3833 is a denial-of-service vulnerability affecting Openwsman versions up to and including 2.6.9, as well as various Fedora and openSUSE distributions utilizing Openwsman. A remote, unauthenticated attacker can trigger an infinite loop in the process_connection() function by sending a specially crafted HTTP request. This vulnerability has a CVSS v3.1 score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. There is no evidence of active exploitation, nor are there publicly available exploit modules like Metasploit or Nuclei, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.9CPE matchmatch criteria | cpe:2.3:a:openwsman_project:openwsman:*:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-3833
Dec 10, 2024CVE-2019-3833
Nov 12, 2024CVE-2019-3833
Oct 8, 2024Openwsman versions up to and including 2.6.9 are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
Mar 12, 2019openwsman: Infinite loop in process_connection() allows denial of service
Mar 12, 2019