Infinite loop in IPAddress - CVE-2023-50570
Published: March 5, 2024
Vulnerability identifier: #VU87109
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50570
CWE-ID: CWE-835
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop. A local user can consume all available system resources and cause denial of service conditions.
Affected software
IPAddress
Cloud Pak for Network Automation
Cloud Pak for Network Automation
How to mitigate CVE-2023-50570
Install updates from vendor's website.
IPAddress - update to 5.2.0
Cloud Pak for Network Automation - update to 2.7
Cloud Pak for Network Automation - update to 2.7