CVE Bulletin

CVE-2024-32038

Written by Mission Secure | Apr 19, 2024 6:14:00 PM

CVE-2024-32038 poses a critical threat to OT environments by allowing remote attackers to execute arbitrary code or cause denial of service through a vulnerability in specific industrial control systems. The exploit could lead to widespread disruption in critical infrastructure sectors such as energy, manufacturing, and transportation.

From the CVE database:

Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow hazard in wazuh-analysisd when handling Unicode characters from Windows Eventchannel messages. It impacts Wazuh Manager 3.8.0 and above. This vulnerability is fixed in Wazuh Manager 4.7.2.

https://cve.org/CVERecord?id=CVE-2024-32038