CVE-2024-24458

An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.
Configurations

No configuration.

History

31 Mar 2025, 21:15

Type Values Removed Values Added
Summary (en) An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload. (en) An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.
References
  • () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04780en_us&docLocale=en_US -
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.9

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) Un acceso a memoria no válido al manejar mensajes de transferencia de configuración de ENB que contienen identidades PLMN no válidas en Athonet vEPC MME v11.4.0 permite a los atacantes provocar una denegación de servicio (DoS) a la red celular al iniciar conexiones repetidamente y enviar un payload manipulado.

15 Nov 2024, 21:35

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

15 Nov 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 20:15

Updated : 2025-03-31 21:15


NVD link : CVE-2024-24458

Mitre link : CVE-2024-24458

CVE.ORG link : CVE-2024-24458


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read