← back
CVE-2023-38502

TDengine Database Denial-of-Service

CVSS 6.5 MEDIUMEPSS 0.6%CWE-20
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Jul 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF nested query. This issue affects TDengine Databases which let users connect and run arbitrary queries. Version 3.0.7.1 has a patch for this issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
taosdata · TDengine

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →