CVE-2024-56430
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Dec 25, 2024
Updated: Dec 26, 2024
CWE ID 476
Summary
CVE-2024-56430 is a newly disclosed vulnerability affecting OpenFHE versions up to 1.2.3. This issue involves a NULL pointer dereference in the BinFHEContext::EvalFloor function within the lib/binfhe-base-scheme.cpp file. If exploited, an attacker could cause the software to crash or potentially execute arbitrary code with the privileges of the affected system. This vulnerability poses a significant risk to users running OpenFHE and is advised to be patched as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.