CVE-2024-25678
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/02/2024
Last modified:
20/06/2025
Description
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:litespeedtech:lsquic:*:*:*:*:*:*:*:* | 4.0.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/litespeedtech/lsquic/commit/515f453556c99d27c4dddb5424898dc1a5537708
- https://github.com/litespeedtech/lsquic/releases/tag/v4.0.4
- https://www.rfc-editor.org/rfc/rfc9001
- https://github.com/litespeedtech/lsquic/commit/515f453556c99d27c4dddb5424898dc1a5537708
- https://github.com/litespeedtech/lsquic/releases/tag/v4.0.4
- https://www.rfc-editor.org/rfc/rfc9001



