#VU128042 Allocation of Resources Without Limits or Throttling in Suricata - CVE-2024-38534
Published: July 11, 2024 / Updated: April 27, 2026
Suricata
Open Information Security Foundation
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the modbus parser when processing crafted modbus traffic. A remote attacker can send specially crafted modbus traffic to cause a denial of service.
The issue can lead to unlimited resource accumulation within a flow. The modbus parser is disabled by default.