CVE-2022-24903 is a heap buffer overflow vulnerability in Rsyslog's TCP syslog reception modules (imtcp, imptcp, imgssapi, imhttp) when processing octet-counted framing. This flaw, affecting products like Debian, FedoraProject, NetApp, and Rsyslog itself, can lead to a denial of service (segfault) or other malfunctions. Rated 8.1 HIGH, the vulnerability has a network attack vector and high impact on confidentiality, integrity, and availability, though exploitation for remote code execution is considered highly complex. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond a single Siemens advisory.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.2204.1CPE matchmatch criteria | cpe:2.3:a:rsyslog:rsyslog:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.