High severity7.5NVD Advisory· Published Feb 3, 2024· Updated Jun 17, 2026
CVE-2024-1064
CVE-2024-1064
Description
A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:craftycontrol:crafty_controller:*:*:*:*:*:*:*:*range: >=4.0.0,<=4.2.2
- Arcadia Technology, LLC/Crafty Controllerv5Range: 4.0.0
Patches
Vulnerability mechanics
References
1- gitlab.com/crafty-controller/crafty-4/-/issues/327nvdExploitIssue Tracking
News mentions
0No linked articles in our index yet.