CVE-2024-47188
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to byte-range tracking having predictable hash table behavior. This can lead to an attacker forcing lots of data into a single hash bucket, leading to severe performance degradation. This issue has been addressed in 7.0.7.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-330
- Published
- 2024-10-16
- Last modified
- 2026-03-13
Affected products
- OISF suricata
Weakness type
Related vulnerabilities
- CVE-2026-53939 — OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
- CVE-2026-86187 — WWBN AVideo Weak PRNG Password Generation via External Login
- CVE-2026-17274 — IBM i is Affected By Multiple Vulnerabilities in Debug Server
- CVE-2026-3416 — Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads
- CVE-2026-66047 — ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE
- CVE-2026-81852 — AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
- CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
- CVE-2026-19485 — Bucket Squatting in Vertex AI Search for Commerce