CVE-2024-24453
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 15, 2024
CWE ID 125
Summary
CVE-2024-24453 is a newly identified vulnerability in Athonet vEPC MME v11.4.0. This issue arises when processing the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information elements in the protocol. Attackers can exploit this vulnerability by sending crafted payloads, resulting in an invalid memory access. Consequently, the cellular network experiences a Denial of Service (DoS) attack as the system becomes overwhelmed with repeated connection attempts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.