CVE-2023-46848
Squid-Cache Squid 5.0.3 – 6.4
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HSummary
CVE-2023-46848 is a high-severity Incorrect Conversion between Numeric Types (CWE-681) vulnerability in Squid-Cache Squid. Its CVSS base score is 8.6 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Squid is affected by CVE-2023-46848, a denial-of-service vulnerability that arises when the proxy processes ftp:// URLs supplied inside HTTP request messages or constructed from native FTP input. The flaw is tracked under CWE-681 and carries a CVSS 3.1 score of 8.6, reflecting network attackability without authentication or user interaction and a scope change that can fully impair availability.
A remote attacker can exploit the issue simply by sending crafted requests containing ftp:// URLs, causing the Squid process to crash or become unresponsive and thereby denying service to legitimate users.
Red Hat has issued multiple security updates (RHSA-2023:6266, RHSA-2023:6268, RHSA-2023:6748) and maintains a Bugzilla entry (2245919) that describe the affected packages and provide patched versions for supported Red Hat products. The associated EPSS probability reached a peak of 0.1042 before declining to its current value of 0.0716.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-51014
Vulnerability Data
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require code reviews, static analysis, and developer training that catch and prevent numeric type-conversion errors.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect numeric conversion defects before release.
Secure development lifecycle includes type-safety and conversion checks that reduce numeric truncation risks.
Application security requirements can mandate safe numeric handling and range validation.
Secure architecture principles promote strong typing and safe conversion practices.
Secure coding standards directly address correct numeric type conversions and overflow checks.