7.8
CVSSv2

CVE-2018-7162

Published: 13/06/2018 Updated: 16/08/2022
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nodejs node.js

Vendor Advisories

All versions of Nodejs 9x and 10x are vulnerable and the severity is HIGH An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash This can be accomplished by sending duplicate/unexpected messages during the handshake This vulnerability has been addressed by updatin ...