CVE-2024-54129

CRITICAL

ION-DTN BPv7 <4.1.3 - DoS

Title source: llm
STIX 2.1

Description

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper reference to the imc scheme with valid Service-Specific Part (SSP) in their Previous Node Block. The vulnerability can cause ION to become unresponsive. This vulnerability is fixed in 4.1.3s.

Scores

CVSS v4 9.2
EPSS 0.0037
EPSS Percentile 58.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-665
Status published
Products (1)
nasa-jpl/ION-DTN < 4.1.3s
Published Dec 05, 2024
Tracked Since Feb 18, 2026