The Open Information Security Foundation maintains Suricata, a widely embedded open-source network intrusion detection and prevention engine that sits on the monitoring edge of many network defenses despite the vendor's focused product portfolio. Vulnerabilities affecting this project skew toward serious outcomes, with a meaningful share reaching critical severity and concentrating in parser-oriented and validation-layer weakness classes including improper input validation and inadequately implemented security checks that are inherent to processing untrusted network traffic. Defenders should treat Suricata updates as priority items for detection and prevention infrastructure; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openinfosecfoundation over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-8954CRITICAL The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functio | Mar 20, 2017 | 9.8 | 25 | NO | NO |
CVE-2017-7177HIGH Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching. | Mar 18, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-15377HIGH In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspec | Oct 23, 2017 | 7.5 | 24 | NO | NO |
CVE-2014-6603MEDIUM The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly hav | Oct 7, 2014 | 5.0 | 21 | NO | NO |
CVE-2015-0971MEDIUM The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates. | May 14, 2015 | 5.0 | 15 | NO | NO |
CVE-2013-5919MEDIUM Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record. | May 30, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openinfosecfoundation.
Media articles that mention a CVE ID that affects a product developed by Openinfosecfoundation — matched by CVE ID, not by vendor name.