GHSA-cm9m-hp76-grcqCriticalCVSS 9.1
The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command...
🔗 CVE IDs covered (1)
📋 Description
The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary data.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2024-45163
- https://cypressthatkid.medium.com/remote-dos-exploit-found-in-mirai-botnet-source-code-27a1aad284f1
- https://pastebin.com/6tqHnCva
- https://youtu.be/aJkvSr85ML8
- https://flowtriq.com/blog/cve-2024-45163-mirai-botnet-kill-switch
- https://traztech.ca/research
- https://github.com/advisories/GHSA-cm9m-hp76-grcq