CVE-2024-7347

MEDIUM EPSS 23.8%
Published Aug 14, 20241y ago · Modified Jun 17, 20261w ago
5.7 CVSS 4.0
Medium
Find Similar
Published Aug 14, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Details

Base Score
5.7
Exploitability
Impact
Vector string
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
23.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 2

CWE-125 Out-of-bounds Read Memory Safety
CWE-126

Affected Products 6

VendorProductVersionRange
f5nginx_open_source*≥1.5.13  –  <1.26.2
f5nginx_open_source1.27.0any
f5nginx_plus*≥r27  –  <r31
f5nginx_plusr31any
f5nginx_plusr31any
f5nginx_plusr32any

References 3

  • openwall.com http://www.openwall.com/lists/oss-security/2024/08/14/4
    Mailing List
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00017.html
  • my.f5.com https://my.f5.com/manage/s/article/K000140529
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.