9.8
CVSSv3

CVE-2024-25678

Published: 09/02/2024 Updated: 15/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In LiteSpeed QUIC (LSQUIC) Library prior to 4.0.4, DCID validation is mishandled.

Vulnerable Product Search on Vulmon Subscribe to Product

litespeedtech lsquic

Github Repositories

QUICTester Total faults found: 55 (3 CVEs assigned) 44 specification violations (An implemented behavior violates the QUIC specification) 8 memory-related bugs (An input causing a memory corruption and a server crash) 3 logic flaws (Incorrect logic implemented in code produces unexpected behavior) CVEs CVE-2023-42805 CVE-2024-25679 CVE-2024-25678 Faults that are resolved