Vulnerability Details CVE-2023-4785
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.2%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-4785
-
cpe:2.3:a:grpc:grpc:1.23.3
-
cpe:2.3:a:grpc:grpc:1.23.4
-
cpe:2.3:a:grpc:grpc:1.24.2
-
cpe:2.3:a:grpc:grpc:1.24.3
-
cpe:2.3:a:grpc:grpc:1.24.4
-
cpe:2.3:a:grpc:grpc:1.25.0
-
cpe:2.3:a:grpc:grpc:1.26.0
-
cpe:2.3:a:grpc:grpc:1.27.0
-
cpe:2.3:a:grpc:grpc:1.27.1
-
cpe:2.3:a:grpc:grpc:1.27.2
-
cpe:2.3:a:grpc:grpc:1.27.3
-
cpe:2.3:a:grpc:grpc:1.28.0
-
cpe:2.3:a:grpc:grpc:1.28.1
-
cpe:2.3:a:grpc:grpc:1.28.2
-
cpe:2.3:a:grpc:grpc:1.29.0
-
cpe:2.3:a:grpc:grpc:1.29.1
-
cpe:2.3:a:grpc:grpc:1.30.0
-
cpe:2.3:a:grpc:grpc:1.30.1
-
cpe:2.3:a:grpc:grpc:1.30.2
-
cpe:2.3:a:grpc:grpc:1.31.0
-
cpe:2.3:a:grpc:grpc:1.31.1
-
cpe:2.3:a:grpc:grpc:1.32.0
-
cpe:2.3:a:grpc:grpc:1.33.0
-
cpe:2.3:a:grpc:grpc:1.33.1
-
cpe:2.3:a:grpc:grpc:1.33.2
-
cpe:2.3:a:grpc:grpc:1.34.0
-
cpe:2.3:a:grpc:grpc:1.34.1
-
cpe:2.3:a:grpc:grpc:1.35.0
-
cpe:2.3:a:grpc:grpc:1.36.0
-
cpe:2.3:a:grpc:grpc:1.36.1
-
cpe:2.3:a:grpc:grpc:1.36.2
-
cpe:2.3:a:grpc:grpc:1.36.3
-
cpe:2.3:a:grpc:grpc:1.36.4
-
cpe:2.3:a:grpc:grpc:1.37.0
-
cpe:2.3:a:grpc:grpc:1.37.1
-
cpe:2.3:a:grpc:grpc:1.38.0
-
cpe:2.3:a:grpc:grpc:1.38.1
-
cpe:2.3:a:grpc:grpc:1.39.0
-
cpe:2.3:a:grpc:grpc:1.39.1
-
cpe:2.3:a:grpc:grpc:1.40.0
-
cpe:2.3:a:grpc:grpc:1.41.0
-
cpe:2.3:a:grpc:grpc:1.41.1
-
cpe:2.3:a:grpc:grpc:1.42.0
-
cpe:2.3:a:grpc:grpc:1.43.0
-
cpe:2.3:a:grpc:grpc:1.43.2
-
cpe:2.3:a:grpc:grpc:1.44.0
-
cpe:2.3:a:grpc:grpc:1.44.1
-
cpe:2.3:a:grpc:grpc:1.45.0
-
cpe:2.3:a:grpc:grpc:1.45.1
-
cpe:2.3:a:grpc:grpc:1.45.2
-
cpe:2.3:a:grpc:grpc:1.45.3
-
cpe:2.3:a:grpc:grpc:1.46.0
-
cpe:2.3:a:grpc:grpc:1.46.1
-
cpe:2.3:a:grpc:grpc:1.46.2
-
cpe:2.3:a:grpc:grpc:1.46.3
-
cpe:2.3:a:grpc:grpc:1.46.4
-
cpe:2.3:a:grpc:grpc:1.46.5
-
cpe:2.3:a:grpc:grpc:1.46.6
-
cpe:2.3:a:grpc:grpc:1.46.7
-
cpe:2.3:a:grpc:grpc:1.47.0
-
cpe:2.3:a:grpc:grpc:1.47.1
-
cpe:2.3:a:grpc:grpc:1.47.2
-
cpe:2.3:a:grpc:grpc:1.47.3
-
cpe:2.3:a:grpc:grpc:1.47.4
-
cpe:2.3:a:grpc:grpc:1.47.5
-
cpe:2.3:a:grpc:grpc:1.48.0
-
cpe:2.3:a:grpc:grpc:1.48.1
-
cpe:2.3:a:grpc:grpc:1.48.2
-
cpe:2.3:a:grpc:grpc:1.48.3
-
cpe:2.3:a:grpc:grpc:1.48.4
-
cpe:2.3:a:grpc:grpc:1.49.0
-
cpe:2.3:a:grpc:grpc:1.49.1
-
cpe:2.3:a:grpc:grpc:1.49.2
-
cpe:2.3:a:grpc:grpc:1.49.3
-
cpe:2.3:a:grpc:grpc:1.50.0
-
cpe:2.3:a:grpc:grpc:1.50.1
-
cpe:2.3:a:grpc:grpc:1.50.2
-
cpe:2.3:a:grpc:grpc:1.51.0
-
cpe:2.3:a:grpc:grpc:1.51.1
-
cpe:2.3:a:grpc:grpc:1.51.2
-
cpe:2.3:a:grpc:grpc:1.51.3
-
cpe:2.3:a:grpc:grpc:1.52.0
-
cpe:2.3:a:grpc:grpc:1.52.1
-
cpe:2.3:a:grpc:grpc:1.52.2
-
cpe:2.3:a:grpc:grpc:1.53.0
-
cpe:2.3:a:grpc:grpc:1.53.1
-
cpe:2.3:a:grpc:grpc:1.54.0
-
cpe:2.3:a:grpc:grpc:1.54.1
-
cpe:2.3:a:grpc:grpc:1.54.2
-
cpe:2.3:a:grpc:grpc:1.55.0
-
cpe:2.3:a:grpc:grpc:1.55.1
-
cpe:2.3:a:grpc:grpc:1.56.0