CVE-2022-38725
CSIRTS triage
- What
- An integer overflow in the RFC3164 syslog parser causes denial of service when processing crafted syslog input.
- Who is affected
- syslog-ng deployments versions 3.0–3.37, Premium Edition 7.0.30, and Store Box 6.10.0 receiving untrusted syslog data.
- Urgency
- High urgency; CVSS 7.5 (high severity), allows remote denial of service without authentication.
- Action
- Upgrade syslog-ng to a patched version after 3.37, Premium Edition after 7.0.30, or Store Box after 6.10.0.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2022-38725
Get an email if CVE-2022-38725 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk2.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 82% of all EPSS-scored CVEs.
Advisory coverage (1)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2022-38725)