Cyber Posture

CVE-2024-57640

HighPublic PoC

Published: 14 January 2025

Published
14 January 2025
Modified
17 April 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score 0.0040 60.7th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

An issue in the dc_add_int component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Security Summary

CVE-2024-57640 is a vulnerability in the dc_add_int component of OpenLink Virtuoso OpenSource version 7.2.11. The issue allows attackers to cause a Denial of Service (DoS) condition through crafted SQL statements. It has been assigned a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) and is associated with CWE-89 (Improper Neutralization of Special Elements used in an SQL Command, or SQL Injection).

The vulnerability can be exploited by unauthenticated remote attackers over the network with low complexity and no user interaction required. Successful exploitation enables high-impact integrity violations, as indicated by the CVSS metrics, potentially allowing manipulation of data integrity without affecting confidentiality or availability directly.

Mitigation details are referenced in the GitHub issue at https://github.com/openlink/virtuoso-opensource/issues/1184, which provides additional context on the vulnerability.

Details

CWE(s)
CWE-89

Affected Products

openlinksw
virtuoso
7.2.11

References