Impact
Suricata’s DNP3 packet reassembly routine allocates memory without limiting the data size it can buffer, leading to uncontrolled memory consumption. An attacker who can generate malicious DNP3 traffic can trigger this flaw, exhausting available system memory and causing the Suricata process to become unresponsive or crash. The weakness is an uncontrolled resource consumption vulnerability.
Affected Systems
All installations of Suricata older than version 7.0.16 or 8.0.5 are affected. These releases include the unbounded reassembly logic; the issue is resolved only in the listed patched versions.
Risk and Exploitability
The CVSS score of 7.5 denotes a high severity. The EPSS score is less than 1%, indicating a low probability of exploitation at present, and the flaw is not in the CISA KEV catalog. Nonetheless, the attack requires only remotely crafted DNP3 traffic, and any deployment with DNP3 enabled or a high reassembly depth could be vulnerable to a denial‑of‑service attack.
OpenCVE Enrichment