Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-2169— Implementations of UDP application protocols are susceptible to network loops and denial of service

Quick assessment

Affected
MikroTik RouterOS-TFTP
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

User Datagram Protocol是用户数据报协议(UDP)。 User Datagram Protocol (UDP)存在安全漏洞,该漏洞源于容易受到网络循环的影响,攻击者利用该漏洞可以使用恶意制作的数据包来攻击设备,从而导致拒绝服务。

AI Predicted 7.5 Difficulty: Trivial EPSS 5.40% · P92
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-2169

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Implementations of UDP application protocols are susceptible to network loops and denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
User Datagram Protocol 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
User Datagram Protocol是用户数据报协议(UDP)。 User Datagram Protocol (UDP)存在安全漏洞,该漏洞源于容易受到网络循环的影响,攻击者利用该漏洞可以使用恶意制作的数据包来攻击设备,从而导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
MikroTik RouterOS-TFTP * ~ 7.13.2 -
Microsoft WDS * -
dproxy-nexgen dproxy-nexgen 0.1 ~ 0.5 -

II. Public POCs for CVE-2024-2169

# POC Description Source Link Shenlong Link
1 This Python script automates the process of scanning for systems potentially vulnerable to the Loop DoS attack and the hypothetical CVE-2024-2169 vulnerability. It focuses on scanning ports associated with protocols susceptible to denial-of-service (DoS) attacks. The script can be used for educational purposes or authorized penetration testing. https://github.com/douglasbuzatto/G3-Loop-DoS POC Details
2 This Python script automates the process of scanning for systems potentially vulnerable to the Loop DoS attack and the hypothetical CVE-2024-2169 vulnerability. It focuses on scanning ports associated with protocols susceptible to denial-of-service (DoS) attacks. The script can be used for educational purposes or authorized penetration testing. https://github.com/renancesarr/G3-Loop-DoS POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-2169

请登录查看更多情报信息。

Vendor Advisories for CVE-2024-2169 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2024-2169

No comments yet


Leave a comment