CVE-2023-45319 describes an unauthenticated remote Denial of Service (DoS) vulnerability affecting Perforce Helix Core versions prior to 2023.2, specifically via the commit function. This flaw carries a CVSS score of 7.5 (HIGH), indicating it can be exploited over the network with low attack complexity, requiring no user interaction or privileges, and resulting in a complete loss of availability. While not listed in CISA's KEV catalog and lacking public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, including a BleepingComputer article that incorrectly reported it as an RCE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023.2CPE matchmatch criteria | cpe:2.3:a:perforce:helix_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.