CVE-2024-24453

An invalid memory access when handling the ProtocolIE_ID field ofE-RAB NotToBeModifiedBearerModInd information element inAthonet vEPC MME v11.4.0 allows attackers to cause a Denial ofService (DoS) to the cellular network by repeatedly initiatingconnections and sending a crafted payload.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
hpeCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H