CVE-2024-24455
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 15, 2024
CWE ID 125
Summary
CVE-2024-24455 is a newly disclosed cybersecurity vulnerability affecting Athonet vEPC MME v11.4.0. This issue arises when the system fails to validate UE identifiers in UE Context Release messages, leading to an invalid memory access. Malicious actors can exploit this flaw by repeatedly initiating connections and sending crafted payloads. The consequence of successful exploitation is a Denial of Service (DoS) attack against the cellular network. The vulnerability poses a significant risk to network availability and reliability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.