In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade kdeconnect | Oct 22, 2020 | Oct 7, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 7, 2020 |
| Debian | — | Upgrade kdeconnect | Jul 30, 2024 | Oct 7, 2020 |
| Freebsd | — | Upgrade kdeconnect-kde | Oct 5, 2020 | Oct 4, 2020 |
| Gentoo Linux | — | Upgrade kde-misc/kdeconnect. | Jan 25, 2021 | Oct 7, 2020 |
| Suse | — | Upgrade kdeconnect-kde-zsh-completionUpgrade kdeconnect-kde-langUpgrade kdeconnect-kde | Oct 8, 2020 | Oct 2, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 7, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub