CVE-2024-56316

In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenticated attackers to cause a permanent Denial of Service via crafted TR069 requests on TCP port 9675 or 7547. Rebooting does not resolve the permanent Denial of Service.
Configurations

No configuration.

History

28 Jan 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-770

27 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 23:15

Updated : 2025-01-28 20:15


NVD link : CVE-2024-56316

Mitre link : CVE-2024-56316

CVE.ORG link : CVE-2024-56316


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling