CVE-2024-21173 is a denial-of-service vulnerability affecting Oracle MySQL Server versions 8.0.37 and prior, and 8.4.0 and prior, specifically within the InnoDB component. A highly privileged attacker with network access can exploit this vulnerability to cause a complete and repeatable crash of the MySQL Server. With a CVSS 3.1 Base Score of 4.9 (Medium), the attack requires high privileges but has low attack complexity, impacting only availability. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.37CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
8.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:8.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-21173
Dec 10, 2024CVE-2024-21173
Nov 12, 2024CVE-2024-21173
Oct 8, 2024mysql: InnoDB unspecified vulnerability (CPU Jul 2024)
Jul 16, 2024Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Jul 9, 2024