CVE-2023-7340 identifies a heap-buffer overflow vulnerability within the Wazuh authd component, which attackers can exploit by sending specially crafted input to cause memory corruption. This flaw, rated Medium (CVSS 4.3), has a network attack vector with low complexity but requires user interaction. Successful exploitation can lead to a denial of service condition for the authentication daemon, impacting its availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, <= 4.3.10CPE match | cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* | ||
<= 3.5.0CPE matchmatch criteria | cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:* | ||
4.3.10CPE matchmatch criteria | cpe:2.3:a:wazuh:wazuh:4.3.10:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.