Cyber Posture

CVE-2024-57617

HighPublic PoC

Published: 14 January 2025

Published
14 January 2025
Modified
10 April 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0022 44.1th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

An issue in the dameraulevenshtein component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Security Summary

CVE-2024-57617 is a vulnerability in the dameraulevenshtein component of MonetDB Server version 11.49.1. The flaw allows attackers to trigger a Denial of Service (DoS) condition by sending crafted SQL statements. It is associated with CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating high severity primarily due to availability impact.

Remote attackers can exploit this vulnerability without authentication, privileges, or user interaction, as it is network-accessible with low attack complexity. Successful exploitation results in a DoS, disrupting the availability of the MonetDB Server while having no impact on confidentiality or integrity.

Mitigation details are available in the referenced GitHub issue at https://github.com/MonetDB/MonetDB/issues/7432.

Details

CWE(s)
CWE-89

Affected Products

monetdb
monetdb
11.49.1

References