Crafted Payload Can Cause Denial of Service to Cellular Network
CVE-2024-24457
5.9MEDIUM
What is CVE-2024-24457?
An invalid memory access issue arises when processing the ProtocolIE_ID field within E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0. This vulnerability permits attackers to create a denial of service condition in the cellular network by persistently establishing connections and transmitting specially crafted data payloads, effectively disrupting normal operations.
Affected Version(s)
HPE Athonet Core HPE Athonet Core 11.0 <= 11.6
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published