CVE-2024-38355 is a denial-of-service vulnerability affecting Socket.IO, an open-source real-time communication framework, where a specially crafted packet can crash the Node.js server process. Rated 7.3 HIGH, this vulnerability has a network attack vector, low attack complexity, and can lead to low impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, Siemens has issued an advisory regarding its impact on their industrial products, indicating some industry awareness. The issue is resolved in Socket.IO versions 4.6.2 and later, and a backport is available for the 2.x branch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Socketio | Socket.Io | < 2.5.1, >= 3.0.0,< 4.6.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.