CVE-2024-45163: Mirai Botnet

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary data.

Affected products

  • Mirai Botnet: up to and including 2024-08-19

Published 2024-08-22. Last modified 2026-09-16.