Описание
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.30 (исключая)
cpe:2.3:a:ericsson:packet_core_gateway:*:*:*:*:*:*:*:*
EPSS
Процентиль: 6%
0.00165
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-230
Связанные уязвимости
CVSS3: 6.5
github
3 месяца назад
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
EPSS
Процентиль: 6%
0.00165
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-230