Uncaught Exception in socket.io-parser - CVE-2023-32695

 

Uncaught Exception in socket.io-parser - CVE-2023-32695

Published: July 21, 2023


Vulnerability identifier: #VU78488
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32695
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling. A remote attacker can send a specially crafted Socket.IO packet to the application and perform a denial of service (DoS) attack.


Affected software

socket.io-parser
Splunk User Behavior Analytics (UBA)
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
Dell Data Protection Central
IBM Planning Analytics Workspace
Storage Protect Plus Server
HPE Unified OSS Console (UOC)

How to mitigate CVE-2023-32695

Install updates from vendor's website.

socket.io-parser - update to 4.2.3
Splunk User Behavior Analytics (UBA) - addressed in versions 5.2.1, 5.3.0
Dell Data Protection Central - update to 19.12.0-2
IBM Planning Analytics Workspace - update to 2.0.94
HPE Unified OSS Console (UOC) - update to 3.1.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 8.2.0
Storage Protect Plus Server - update to 10.1.16.3

External References

Related Security Bulletins