Vulnerability Details CVE-2023-35853
In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 66.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-35853
-
cpe:2.3:a:oisf:suricata:-
-
cpe:2.3:a:oisf:suricata:0.8.2
-
cpe:2.3:a:oisf:suricata:1.0.0
-
cpe:2.3:a:oisf:suricata:1.0.1
-
cpe:2.3:a:oisf:suricata:1.0.2
-
cpe:2.3:a:oisf:suricata:1.0.3
-
cpe:2.3:a:oisf:suricata:1.0.4
-
cpe:2.3:a:oisf:suricata:1.0.5
-
cpe:2.3:a:oisf:suricata:1.1
-
cpe:2.3:a:oisf:suricata:1.1.1
-
cpe:2.3:a:oisf:suricata:1.2
-
cpe:2.3:a:oisf:suricata:1.2.1
-
cpe:2.3:a:oisf:suricata:1.3
-
cpe:2.3:a:oisf:suricata:1.3.1
-
cpe:2.3:a:oisf:suricata:1.3.2
-
cpe:2.3:a:oisf:suricata:1.3.3
-
cpe:2.3:a:oisf:suricata:1.3.4
-
cpe:2.3:a:oisf:suricata:1.3.5
-
cpe:2.3:a:oisf:suricata:1.3.6
-
cpe:2.3:a:oisf:suricata:1.4
-
cpe:2.3:a:oisf:suricata:1.4.1
-
cpe:2.3:a:oisf:suricata:1.4.2
-
cpe:2.3:a:oisf:suricata:1.4.3
-
cpe:2.3:a:oisf:suricata:1.4.4
-
cpe:2.3:a:oisf:suricata:1.4.5
-
cpe:2.3:a:oisf:suricata:1.4.6
-
cpe:2.3:a:oisf:suricata:1.4.7
-
cpe:2.3:a:oisf:suricata:2.0
-
cpe:2.3:a:oisf:suricata:2.0.1
-
cpe:2.3:a:oisf:suricata:2.0.10
-
cpe:2.3:a:oisf:suricata:2.0.11
-
cpe:2.3:a:oisf:suricata:2.0.2
-
cpe:2.3:a:oisf:suricata:2.0.3
-
cpe:2.3:a:oisf:suricata:2.0.4
-
cpe:2.3:a:oisf:suricata:2.0.5
-
cpe:2.3:a:oisf:suricata:2.0.6
-
cpe:2.3:a:oisf:suricata:2.0.7
-
cpe:2.3:a:oisf:suricata:2.0.8
-
cpe:2.3:a:oisf:suricata:2.0.9
-
cpe:2.3:a:oisf:suricata:2.1
-
cpe:2.3:a:oisf:suricata:3.0
-
cpe:2.3:a:oisf:suricata:3.0.1
-
cpe:2.3:a:oisf:suricata:3.0.2
-
cpe:2.3:a:oisf:suricata:3.1
-
cpe:2.3:a:oisf:suricata:3.1.1
-
cpe:2.3:a:oisf:suricata:3.1.2
-
cpe:2.3:a:oisf:suricata:3.1.3
-
cpe:2.3:a:oisf:suricata:3.1.4
-
cpe:2.3:a:oisf:suricata:3.2
-
cpe:2.3:a:oisf:suricata:3.2.1
-
cpe:2.3:a:oisf:suricata:3.2.2
-
cpe:2.3:a:oisf:suricata:3.2.3
-
cpe:2.3:a:oisf:suricata:3.2.4
-
cpe:2.3:a:oisf:suricata:3.2.5
-
cpe:2.3:a:oisf:suricata:4.0.0
-
cpe:2.3:a:oisf:suricata:4.0.1
-
cpe:2.3:a:oisf:suricata:4.0.2
-
cpe:2.3:a:oisf:suricata:4.0.3
-
cpe:2.3:a:oisf:suricata:4.0.4
-
cpe:2.3:a:oisf:suricata:4.0.5
-
cpe:2.3:a:oisf:suricata:4.0.6
-
cpe:2.3:a:oisf:suricata:4.0.7
-
cpe:2.3:a:oisf:suricata:4.1.0
-
cpe:2.3:a:oisf:suricata:4.1.1
-
cpe:2.3:a:oisf:suricata:4.1.10
-
cpe:2.3:a:oisf:suricata:4.1.2
-
cpe:2.3:a:oisf:suricata:4.1.3
-
cpe:2.3:a:oisf:suricata:4.1.4
-
cpe:2.3:a:oisf:suricata:4.1.5
-
cpe:2.3:a:oisf:suricata:4.1.6
-
cpe:2.3:a:oisf:suricata:4.1.7
-
cpe:2.3:a:oisf:suricata:4.1.8
-
cpe:2.3:a:oisf:suricata:4.1.9
-
cpe:2.3:a:oisf:suricata:5.0.0
-
cpe:2.3:a:oisf:suricata:5.0.1
-
cpe:2.3:a:oisf:suricata:5.0.10
-
cpe:2.3:a:oisf:suricata:5.0.2
-
cpe:2.3:a:oisf:suricata:5.0.3
-
cpe:2.3:a:oisf:suricata:5.0.4
-
cpe:2.3:a:oisf:suricata:5.0.5
-
cpe:2.3:a:oisf:suricata:5.0.6
-
cpe:2.3:a:oisf:suricata:5.0.7
-
cpe:2.3:a:oisf:suricata:5.0.8
-
cpe:2.3:a:oisf:suricata:5.0.9
-
cpe:2.3:a:oisf:suricata:6.0.0
-
cpe:2.3:a:oisf:suricata:6.0.1
-
cpe:2.3:a:oisf:suricata:6.0.10
-
cpe:2.3:a:oisf:suricata:6.0.11
-
cpe:2.3:a:oisf:suricata:6.0.12
-
cpe:2.3:a:oisf:suricata:6.0.2
-
cpe:2.3:a:oisf:suricata:6.0.3
-
cpe:2.3:a:oisf:suricata:6.0.4
-
cpe:2.3:a:oisf:suricata:6.0.5
-
cpe:2.3:a:oisf:suricata:6.0.6
-
cpe:2.3:a:oisf:suricata:6.0.7
-
cpe:2.3:a:oisf:suricata:6.0.8
-
cpe:2.3:a:oisf:suricata:6.0.9