{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3onetgearr7000p_firmware1.3.3.154/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:netgear:r8500_firmware:1.0.2.160:*:*:*:*:*:*:*","cpe:2.3:o:netgear:xr300_firmware:1.0.3.78:*:*:*:*:*:*:*","cpe:2.3:o:netgear:r7000p_firmware:1.3.3.154:*:*:*:*:*:*:*","cpe:2.3:o:netgear:r6400v2_firmware:1.0.4.128:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.7,"id":"CVE-2024-52013"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rsyslog"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","linux"],"_cs_type":"advisory","_cs_vendors":["Rsyslog"],"content_html":"\u003cp\u003eThe BSI has reported a vulnerability in rsyslog, a widely used logging system for Linux environments. The flaw allows a remote, unauthenticated attacker to trigger a denial of service (DoS) condition on affected systems. This issue, tracked as CVE-2024-52013, stems from improper validation and handling of specific network-based inputs processed by the rsyslog daemon. By sending malformed or specially crafted network requests to the rsyslog service, an attacker can crash the logging process, preventing the collection of system logs and potentially impacting downstream security monitoring or operational audit requirements. Defenders should prioritize updating to the latest stable release to mitigate the risk of service disruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate termination of the rsyslog process. In enterprise environments, this impacts centralized log aggregation, security information and event management (SIEM) data ingestion, and the visibility of system events necessary for incident response and compliance monitoring. Organizations relying on rsyslog for infrastructure-wide logging are vulnerable to monitoring blindness if the service is successfully exploited.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor system logs and process management logs for unexpected termination of the rsyslog process.\u003c/li\u003e\n\u003cli\u003eEnsure rsyslog is updated to the latest vendor-supplied version that includes the fix for CVE-2024-52013.\u003c/li\u003e\n\u003cli\u003eRestrict network access to rsyslog listeners to trusted management subnets using host-based firewalls (iptables/nftables).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T13:51:35Z","date_published":"2026-09-21T13:51:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rsyslog-dos/","summary":"A vulnerability in rsyslog allows a remote, unauthenticated attacker to cause a denial-of-service condition through improper handling of network inputs.","title":"Denial of Service Vulnerability in rsyslog","url":"https://feed.craftedsignal.io/briefs/2026-09-rsyslog-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:netgear:r7000p_firmware:1.3.3.154:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}