Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-7347

18
FAUCET Score

CVE-2024-7347 is a vulnerability in NGINX Open Source and NGINX Plus, specifically within the ngx_http_mp4_module, that could lead to worker memory over-read and service termination. This issue affects NGINX installations configured to use the mp4 directive and built with the ngx_http_mp4_module. The vulnerability has a CVSS score of 4.7 (MEDIUM), indicating a local attack vector with high attack complexity, requiring low privileges, and resulting in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog. Community discussion and media coverage are minimal, with only one article noting a fix in recent NGINX releases.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.5.13, < 1.26.2CPE matchmatch criteria
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
1.27.0CPE matchmatch criteria
cpe:2.3:a:f5:nginx_open_source:1.27.0:*:*:*:*:*:*:*
>= r27, < r31CPE matchmatch criteria
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
r31CPE matchmatch criteria
cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:*
r31CPE matchmatch criteria
cpe:2.3:a:f5:nginx_plus:r31:p1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.7MEDIUM

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 72nd percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

dahuapatch availablevia llm_extracted
Fixed in: 1.26.2+
View patch
dfinitypatch availablevia llm_extracted
Fixed in: 1.27.1
View patch
jfrogpatch availablevia llm_extracted
Fixed in: 1.27.1
View patch
liferaypatch availablevia llm_extracted
Fixed in: 1.26.2
View patch
microsoftpatch availablevia msrc
Product: 17256-16823Fixed in: 1.22.1-12
microsoftpatch availablevia msrc
Product: 20144-17086Fixed in: 1.22.1-12
microsoftpatch availablevia msrc
Product: 17658-17084Fixed in: 1.25.4-2
microsoftpatch availablevia msrc
Product: 19860-17084Fixed in: 1.25.4-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 1.25.4-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 1.25.4-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.22.1-12
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.22.1-12
microsoftpatch availablevia msrc
Product: cbl2 nginx 1.22.1-12 on CBL Mariner 2.0Fixed in: 1.22.1-12
microsoftpatch availablevia msrc
Product: cbl2 nginx 1.22.1-13 on CBL Mariner 2.0Fixed in: 1.22.1-12
microsoftpatch availablevia msrc
Product: azl3 nginx 1.25.4-2 on Azure Linux 3.0Fixed in: 1.25.4-2
microsoftpatch availablevia msrc
Product: azl3 nginx 1.25.4-4 on Azure Linux 3.0Fixed in: 1.25.4-2
netgearpatch availablevia llm_extracted
Fixed in: 1.27.1+, 1.26.2+
View patch
opensshpatch availablevia llm_extracted
Fixed in: 1.27.1
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.26.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nginx:1.22-9050020250324053651.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: nginx-1:1.20.1-14.el9_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: nginx:1.24-9040020250414212413.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: nginx:1.22-9040020250408102234.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: nginx-1:1.20.1-16.el9_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: nginx:1.22-9020020250414211356.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nginx-2:1.20.1-22.el9_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nginx:1.24-9050020250324055038.9
View patch
terraformpatch availablevia llm_extracted
Fixed in: 1.27.1
View patch
redhatend of lifevia redhat_api
Product: Red Hat Ansible Automation Platform 1.2Fixed in: nginx
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nginx:1.22/nginx
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nginx:1.24/nginx

Vendor Advisories (12)

microsoft2024-Dec/CVE-2024-7347

CVE-2024-7347

Dec 10, 2024
microsoft2024-Oct/CVE-2024-7347

CVE-2024-7347

Oct 8, 2024
redhatCVE-2024-7347Moderate

nginx: specially crafted MP4 file may cause denial of service

Aug 14, 2024
microsoft2024-Aug/CVE-2024-7347Moderate

NGINX MP4 module vulnerability

Aug 13, 2024
dfinityllm-dfinity-c0f5c53851012dfdLOW

Buffer overread in the ngx_http_mp4_module

Jan 1, 2024
opensshllm-openssh-7751f65e5f752229LOW

Buffer overread in the ngx_http_mp4_module

Jan 1, 2024
power_billm-power_bi-1a4fac66e0d34318LOW

Buffer overread in the ngx_http_mp4_module

Jan 1, 2024
liferayllm-liferay-c0d89350c1f35422LOW

Buffer overread in the ngx_http_mp4_module

Jan 1, 2024
jfrogllm-jfrog-e290ca6f0b365223LOW

Buffer overread in the ngx_http_mp4_module

Jan 1, 2024
terraformllm-terraform-81c65661bb21a88fLOW

Buffer overread in the ngx_http_mp4_module

dahuallm-dahua-076663ac996d339dLOW

Buffer overread in the ngx_http_mp4_module

netgearllm-netgear-bef79f4af36a1e94LOW

Buffer overread in the ngx_http_mp4_module

References

lists.debian.org / debian-lts-announce/2025/03/msg00017.html
openwall.com / lists/oss-security/2024/08/14/4
Mailing List
my.f5.com / manage/s/article/K000140529
Vendor Advisory