New ‘Loop DoS’ attack may impact up to 300,000 online systems
ID: f70db14f-1f00-595b-8548-43eb6a8fc3a8
STIX ID: report--f70db14f-1f00-595b-8548-43eb6a8fc3a8
Feed Name: Bleeping Computer
A newly disclosed UDP implementation vulnerability (CVE-2024-2169), dubbed "Loop DoS," allows an attacker to use IP spoofing to pair vulnerable application-layer services into an indefinite response loop that generates unbounded traffic, potentially causing service- or network-level denial-of-service for an estimated 300,000 hosts; vendors including Broadcom, Cisco, Honeywell, Microsoft, and MikroTik have confirmed affected implementations. CERT/CC and CISPA recommend patching, anti-spoofing (BCP38, uRPF), firewall/ACLs, disabling unnecessary UDP services, and QoS limits to mitigate risk; researchers reported no active exploitation at the time of disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
