CVE-2023-4785

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
grpcgrpc
1.23.0 ≤
𝑥
< 1.53.2
grpcgrpc
1.54.0 ≤
𝑥
< 1.54.3
grpcgrpc
1.55.0 ≤
𝑥
< 1.55.3
grpcgrpc
1.56.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
grpcgrpc
𝑥
< 1.23
ADP
grpcgrpc
1.56.0 ≤
𝑥
≤ 1.56.1
ADP
grpcgrpc
1.55.0 ≤
𝑥
≤ 155.2
ADP
grpcgrpc
1.54.0 ≤
𝑥
≤ 1.54.2
ADP
grpcgrpc
1.53.0 ≤
𝑥
≤ 1.53.1
ADP
Debian logo
Debian Releases
Debian Product
Codename
grpc
bookworm
no-dsa
bullseye
no-dsa
buster
no-dsa
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grpc
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
ignored
mantic
ignored
noble
needs-triage
oracular
needs-triage
trusty
ignored
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
grpc-devel
suse enterprise desktop 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise desktop 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise sap 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise sap 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise server 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise server 15 SP7
1.60.0-150600.15.3.1
fixed
libgrpc++1_60
suse enterprise desktop 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise desktop 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise desktop 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise sap 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise sap 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise sap 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise server 15 SP4
1.60.0-150400.8.3.2
fixed
suse enterprise server 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise server 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise server 15 SP7
1.60.0-150600.15.3.1
fixed
libgrpc1_60
suse enterprise desktop 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise desktop 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise desktop 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise sap 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise sap 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise sap 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise server 15 SP4
1.60.0-150400.8.3.2
fixed
suse enterprise server 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise server 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise server 15 SP7
1.60.0-150600.15.3.1
fixed
libgrpc37
suse enterprise desktop 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise desktop 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise desktop 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise sap 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise sap 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise sap 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise server 15 SP4
1.60.0-150400.8.3.2
fixed
suse enterprise server 15 SP5
1.60.0-150400.8.3.2
fixed
suse enterprise server 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise server 15 SP7
1.60.0-150600.15.3.1
fixed
libupb37
suse enterprise desktop 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise desktop 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise sap 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise sap 15 SP7
1.60.0-150600.15.3.1
fixed
suse enterprise server 15 SP6
1.60.0-150600.13.6
fixed
suse enterprise server 15 SP7
1.60.0-150600.15.3.1
fixed