CVE-2024-21452

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 1, 2024
Updated: Jan 13, 2025
CWE ID 20

Summary

CVE-2024-21452 is a newly identified transient Denial of Service (DoS) vulnerability. It arises when decoding an ASN.1 Object Identifier (OID) Extensible Reporting Structure (OER) message containing an unexpected sequence of extensions. This issue may cause the decoder to crash or consume excessive resources, rendering the affected system temporarily unavailable. Although the exact impact varies based on the decoder implementation, it is crucial for organizations to apply relevant patches or updates upon release to mitigate the potential risks of this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share