VYPR

CWE-617

Reachable Assertion

BaseDraft

Description

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (859)

page 7 of 43
  • CVE-2023-33044HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Data modem while handling TLB control messages from the Network.

  • CVE-2023-33043HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.

  • CVE-2023-33041HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.

  • CVE-2023-40462HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the…

  • CVE-2023-32846HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2023-32845HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2023-32844HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2023-32843HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2023-32842HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2023-32841HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2023-24843HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Modem while triggering a camping on an 5G cell.

  • CVE-2023-32820HigOct 2, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.

  • CVE-2023-4236HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.02

    A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions…

  • CVE-2023-21653HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Modem while processing RRC reconfiguration message.

  • CVE-2023-21646HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Modem while processing invalid System Information Block 1.

  • CVE-2023-39949HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS…

  • CVE-2023-39534HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a…

  • CVE-2023-34868HigJun 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start at jerry-core/parser/js/js-parser-statm.c.

  • CVE-2023-34867HigJun 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at jerry-core/ecma/base/ecma-property-hashmap.c.

  • CVE-2022-40538HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network.