Impact
The vulnerability allows a malicious Suricata rule to overwrite any file on the system when the rule is loaded or reloaded. It stems from improper handling of filenames in the "save" directive, resulting in an arbitrary file write that could compromise system data or configuration.
Affected Systems
Suricata installations older than version 7.0.16 on the 7.x branch or older than 8.0.5 on the 8.x branch are affected. These releases are distributed by OISF and are commonly employed in IDS/IPS environments that use custom or third‑party rule sets.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Exploitation requires the attacker to be able to load a crafted rule, which triggers the arbitrary write. Workarounds are available by sanitizing rule files, limiting Suricata’s write permissions, and applying the recommended configuration changes.
OpenCVE Enrichment