2024年6月

本公告载明可能影响部分谦川科技软件产品、组件或版本的安全漏洞信息。谦川科技高度重视产品及客户业务的安全。截至本公告发布之日,谦川科技尚未收到有关上述漏洞已在真实环境中被利用的报告。


类别漏洞详情
产品名称Hypervisor
受影响的版本MT8676 2os、MT8676 3os、MT8678 2os、MT8678 3os、cobranch、MT8668 2os、MT8668 3os
漏洞编号CVE-2023-45288
CVSS评分5.9
漏洞标题HTTP/2 CONTINUATION flood in net/http
详细描述An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.
受影响资产Nebula 
漏洞类型cve
风险等级中危
修复状态已修复


类别漏洞详情
产品名称Hypervisor
受影响的版本MT8676 2os、MT8676 3os、MT8678 2os、MT8678 3os、cobranch、MT8668 2os、MT8668 3os
漏洞编号CVE-2023-0464
CVSS评分7.5
漏洞标题Excessive Resource Usage Verifying X.509 Policy Constraints
详细描述A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
受影响资产Nebula 
漏洞类型cve
风险等级高危
修复状态已修复


我们坚持以技术创新
开启智能出行新未来
联系我们
邮箱:contact@goldenrivertek.com
Copyright ©2025-2026 宁波谦川科技有限公司版权所有 浙ICP备2022031744号-1