Vulnerabilities > CVE-2024-25679 - Unspecified vulnerability in Pquic
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
LOW Summary
In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |