CVE-2023-31621 describes a Denial of Service (DoS) vulnerability in the kc_var_col component of OpenLink Virtuoso open-source version 7.2.9, which can be triggered by crafted SQL statements. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating it is remotely exploitable with low attack complexity and can lead to a complete loss of availability. There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Furthermore, the vulnerability has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.2.9CPE matchmatch criteria | cpe:2.3:a:openlinksw:virtuoso:7.2.9:*:*:*:open_source:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.