CVE-2023-50923: CSRF

Published Feb 20, 2024
·
Updated

In QUIC in RFC 9000, the Latency Spin Bit specification (section 17.4) does not strictly constrain the bit value when the feature is disabled, which might allow remote attackers to construct a covert channel with data represented as changes to the bit value. NOTE: The "Sheridan, S., Keane, A. (2015). In Proceedings of the 14th European Conference on Cyber Warfare and Security (ECCWS), University of Hertfordshire, Hatfield, UK." paper says "Modern Internet communication protocols provide an almost infinite number of ways in which data can be hidden or embed whithin seemingly normal network traffic."

Affected Software

1 affected component
IETF QUIC (RFC 9000)=RFC 9000

Event History

Feb 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 21, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-50923?

CVE-2023-50923 is considered a medium severity vulnerability due to its potential to enable covert communication channels.

2

How do I fix CVE-2023-50923?

Currently, there are no official fixes for CVE-2023-50923, but monitoring and restricting the use of the Latency Spin Bit feature may help mitigate risk.

3

Who is affected by CVE-2023-50923?

CVE-2023-50923 affects implementations of the IETF QUIC (RFC 9000) protocol that utilize the Latency Spin Bit feature.

4

What impact does CVE-2023-50923 have on network security?

CVE-2023-50923 may allow remote attackers to create covert channels for unauthorized data transmission, potentially compromising network security.

5

What does the Latency Spin Bit refer to in the context of CVE-2023-50923?

The Latency Spin Bit is a feature in the QUIC protocol meant to indicate changes in latency, but its lack of strict constraints when disabled poses a security risk in CVE-2023-50923.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203