KEVIntel
7.5
CVSS
High

CVE-2023-33297

PUBLISHED

Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Bitcoin
Product
Bitcoin Core
Published
May 22, 2023
EPSS

Description

Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.

CVSS scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploitation status

Exploited in the wild

Recorded 2023-05-22 00:00:00 UTC · Source

SSVC decision points

Exploitation
none
Automatable
No
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE May 22, 2023

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel