CVE-2024-1309 is an Uncontrolled Resource Consumption vulnerability affecting Honeywell Niagara Framework versions prior to Niagara AX 3.8.1 and Niagara 4.1 on Windows, Linux, and QNX, leading to Content Spoofing. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-exploitable flaw with low attack complexity that can cause high availability impact without requiring user interaction or privileges. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including an article highlighting its potential for a "Loop DoS Attack."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8.1CPE matchmatch criteria | cpe:2.3:a:honeywell:niagara_framework:*:*:*:*:*:linux:*:* | ||
< 3.8.1CPE matchmatch criteria | cpe:2.3:a:honeywell:niagara_framework:*:*:*:*:*:qnx:*:* | ||
< 3.8.1CPE matchmatch criteria | cpe:2.3:a:honeywell:niagara_framework:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.