CVE-2023-48950 describes a Denial of Service (DoS) vulnerability in OpenLink Virtuoso-opensource v7.2.11, specifically within the box_col_len function, which can be triggered by a crafted SELECT statement. This vulnerability carries a CVSS v3.1 score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, leading to a complete loss of availability. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.2.11CPE matchmatch criteria | cpe:2.3:a:openlinksw:virtuoso:7.2.11:*:*:*:open_source:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.