CVE-2023-40308 is a memory corruption vulnerability in SAP CommonCryptoLib that allows an unauthenticated attacker to cause a denial-of-service by crafting a malicious request to an open port. This affects numerous SAP products, including NetWeaver, HANA Database, and Web Dispatcher. With a CVSS score of 7.5 (High), it has a low attack complexity and no user interaction required, leading to high availability impact. While not currently in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.0CPE matchmatch criteria | cpe:2.3:a:sap:commoncryptolib:8.0.0:*:*:*:*:*:*:* | ||
6.50CPE matchmatch criteria | cpe:2.3:a:sap:content_server:6.50:*:*:*:*:*:*:* | ||
7.53CPE matchmatch criteria | cpe:2.3:a:sap:content_server:7.53:*:*:*:*:*:*:* | ||
7.54CPE matchmatch criteria | cpe:2.3:a:sap:content_server:7.54:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:sap:extended_application_services_and_runtime:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.