CVE-2024-24455

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 15, 2024
CWE ID 125

Summary

CVE-2024-24455 is a newly disclosed cybersecurity vulnerability affecting Athonet vEPC MME v11.4.0. This issue arises when the system fails to validate UE identifiers in UE Context Release messages, leading to an invalid memory access. Malicious actors can exploit this flaw by repeatedly initiating connections and sending crafted payloads. The consequence of successful exploitation is a Denial of Service (DoS) attack against the cellular network. The vulnerability poses a significant risk to network availability and reliability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share