Vulnerabilities > CVE-2024-45396 - Reachable Assertion vulnerability in Dena Quicly

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
dena
CWE-617

Summary

Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using quicly. The vulnerability is addressed with commit 2a95896104901589c495bc41460262e64ffcad5c.

Vulnerable Configurations

Part Description Count
Application
Dena
1

Common Weakness Enumeration (CWE)