CVE-2023-50923

In QUIC in RFC 9000, the Latency Spin Bit specification (section 17.4) does not strictly constrain the bit value when the feature is disabled, which might allow remote attackers to construct a covert channel with data represented as changes to the bit value. NOTE: The "Sheridan, S., Keane, A. (2015). In Proceedings of the 14th European Conference on Cyber Warfare and Security (ECCWS), University of Hertfordshire, Hatfield, UK." paper says "Modern Internet communication protocols provide an almost infinite number of ways in which data can be hidden or embed whithin seemingly normal network traffic."
Configurations

No configuration.

History

04 Dec 2024, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-352

21 Nov 2024, 08:37

Type Values Removed Values Added
References () https://arrow.tudublin.ie/nsdcon/2/ - () https://arrow.tudublin.ie/nsdcon/2/ -
References () https://ieeexplore.ieee.org/document/10427406 - () https://ieeexplore.ieee.org/document/10427406 -
References () https://www.rfc-editor.org/rfc/rfc9000.html - () https://www.rfc-editor.org/rfc/rfc9000.html -

22 Feb 2024, 19:07

Type Values Removed Values Added
Summary
  • (es) En QUIC en RFC 9000, la especificación Latency Spin Bit (sección 17.4) no restringe estrictamente el valor del bit cuando la característica está deshabilitada, lo que podría permitir a atacantes remotos construir un canal encubierto con datos representados como cambios en el valor del bit. NOTA: "Sheridan, S., Keane, A. (2015). En Actas de la 14ª Conferencia Europea sobre Guerra Cibernética y Seguridad (ECCWS), Universidad de Hertfordshire, Hatfield, Reino Unido". El artículo dice: "Los protocolos de comunicación de Internet modernos proporcionan un número casi infinito de formas en las que los datos pueden ocultarse o incrustarse en el tráfico de red aparentemente normal".

21 Feb 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 00:15

Updated : 2024-12-04 21:15


NVD link : CVE-2023-50923

Mitre link : CVE-2023-50923

CVE.ORG link : CVE-2023-50923


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)