CVE-2024-37151 - CVE House
Back to Database
Status published Medium CVE-2024-37151

Suricata defrag: IP ID reuse can lead to policy bypass

Vulnerability Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37151

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

suricata
Vulnerable Versions:
>= 6.0.0, < 6.0.20, >= 7.0.0,< 7.0.6

Timeline

Official Publish: July 11th, 2024
Last Modified: November 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses (CWE)