4 ms·
This is on par with publishing a CVE claiming that you can cause a denial-of-service attack against a server by turning the server off.
by AgentME 3y ago
This is on par with publishing a CVE claiming that you can cause a denial-of-service attack against a server by turning the server off.
- dylan604 3y agoBut it's only confirmed to be an outage when the status page says so. Until then, it is only degraded performance
- alyandon 3y agoYou joke but I had to deal with an actual "high score CVE" internally that dealt with a denial-of-service vulnerability that happens when an administrator misconfigures the software. It literally boils down to "if you misconfigure the daemon it won't start == OMG HIGH RATING VULN". I hate security theater. :(
- deleted 3y ago[deleted]
- cvccvroomvroom 3y agoOne solution is there must be a higher bar of peer review to prevent issuance of bogus CVEs. Another approach would be to separate proposed vulns from confirmed/undisclosed ones. Human with good judgement in the loop is necessary to prevent DoS and spam.
- alyandon 3y agoIn this case not only was the CVE a bullshit CVE, it also didn't properly scope the "affected" versions. The end result was that the version of the software we were running didn't even have the option that could potentially be misconfigured to cause the denial-of-service.
- BasedAnon 3y agoEnough security theatre, it's time for security opera
- 0x457 3y agoI remember having a public Hacker One program at one of the companies I worked at... Every day there were reports like that.
- genter 3y agohttps://devblogs.microsoft.com/oldnewthing/20200318-00/?p=103569 https://devblogs.microsoft.com/oldnewthing/20200318-00/?p=10... > Well, yeah. It’s compromised because you compromised it.
- thaumasiotes 3y agoDefinitely works, effect is severe, but requires physical access. Recommendation: no change.