CVE-2024-34048: Out-of-bounds Read
Published Apr 29, 2024
·Updated
O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.
Affected Software
1 affected component
O-ran-sc Ric-plt-e2mgr=6.0.4
Remediation
Patch Available
Event History
Apr 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 30, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34048?
CVE-2024-34048 has a medium severity rating due to the potential for denial of service vulnerabilities.
2
How do I fix CVE-2024-34048?
To mitigate CVE-2024-34048, update the O-RAN SC RIC PLT E2 Manager to version 6.0.5 or higher, which includes the necessary fixes.
3
What specific issue does CVE-2024-34048 address?
CVE-2024-34048 addresses the lack of array size checks in the E2nodeConfigUpdateNotificationHandler, which can lead to a security vulnerability.
4
Which software versions are affected by CVE-2024-34048?
CVE-2024-34048 affects O-RAN SC RIC PLT E2 Manager version 6.0.4.
5
Is CVE-2024-34048 publicly known?
Yes, CVE-2024-34048 is a publicly disclosed vulnerability, as recorded in various security databases like MITRE.