CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

748 vulnerabilities with CWE-617
CVE-2023-37023 HIGH
Open5GS <= 2.6.4 - Denial of Service via Missing MME_UE_S1AP_ID in Uplink NAS Transport Packet
CVSS 8.6
CVE-2023-37021 HIGH
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 8.6
CVE-2023-37020 HIGH
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 8.6
CVE-2023-37019 HIGH
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 8.6
CVE-2023-37018 HIGH
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 8.6
CVE-2023-37017 HIGH
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 8.6
CVE-2023-37016 HIGH
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 8.6
CVE-2023-37015 HIGH
Open5GS <= 2.6.4 - Denial of Service via Malformed S1AP Path Switch Request
CVSS 8.6
CVE-2023-37013 HIGH
Open5GS <= 2.6.4 - Denial of Service via Oversized ASN.1 Packet on S1AP Interface
CVSS 7.3
CVE-2023-37012 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 5.3
CVE-2023-37011 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 S1AP Handover Message
CVSS 6.3
CVE-2023-37010 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet on S1AP Interface
CVSS 6.3
CVE-2023-37009 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Handover Notification
CVSS 6.3
CVE-2023-37008 MEDIUM
Open5GS <= 2.6.4 - Buffer Overflow in S1AP Handler ASN.1 Deserialization
CVSS 5.3
CVE-2023-37007 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 5.3
CVE-2023-37006 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 5.3
CVE-2023-37005 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 5.3
CVE-2023-37004 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 5.3
CVE-2023-37003 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 5.3
CVE-2023-37002 MEDIUM
Open5GS <= 2.6.4 - Denial of Service via Malformed ASN.1 Packet
CVSS 5.3
CVE-2023-37029 HIGH
Magma <= 1.8.0 - Denial of Service via Oversized NAS Packet
CVSS 7.5
CVE-2023-37024 HIGH
Magma <= 1.8.0 - Unauthenticated Denial of Service via Emergency Number List NAS Packet
CVSS 7.5
CVE-2023-52887 MEDIUM
Linux Kernel 5.4-5.4.279 - Reachable Assertion in J1939 XTP RTS Session Handling
CVSS 5.5
CVE-2023-52831 MEDIUM
Linux Kernel < 6.1.64 - Denial of Service via CPU Hotplug Work Queue
CVSS 5.5
CVE-2023-43529 HIGH
Qualcomm 315 5G IoT Modem Firmware - Denial of Service via Malformed IKEv2 Fragment Packet
CVSS 7.5
Details
Vulnerabilities 748