Today > | 10 High | 17 Medium vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-54129

Dec. 5, 2024, 4:15 p.m.

Product(s) Impacted

NASA’s Interplanetary Overlay Network (ION) - ION-DTN BPv7 implementation

  • 4.1.3

Description

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper reference to the imc scheme with valid Service-Specific Part (SSP) in their Previous Node Block. The vulnerability can cause ION to become unresponsive. This vulnerability is fixed in 4.1.3s.

Weaknesses

CWE-665
Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

CWE ID: 665

Date

Published: Dec. 5, 2024, 4:15 p.m.

Last Modified: Dec. 5, 2024, 4:15 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security-advisories@github.com

References

https://github.com/ security-advisories@github.com