CVE-2024-53379 is a heap buffer overflow vulnerability in Real Time Logic LLC's SharkSSL (version from 05/05/24, commit 64808a5e12c83b38f85c943dee0112e428dc2a43), specifically within the server site handshake implementation. This flaw allows a remote unauthenticated attacker to trigger a Denial-of-Service (DoS) by sending a malformed Client-Hello message. Rated with a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and requires no user interaction, leading to a high impact on availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.