Impact
The vulnerability is a null pointer dereference in the as_rrc module of ASR Crane and Falcon Linux devices, located in the file urrsir.c. The flaw can be triggered through pointer manipulation, potentially causing the process that uses the module to crash or behave unpredictably. The weakness is identified as CWE‑476 and may result in denial of service or instability of the affected service, though no explicit mention of code execution is provided in the CVE description.
Affected Systems
The vulnerability affects ASR Crane and Falcon Linux devices. No specific product versions are identified, so all releases may be susceptible until a vendor‑issued fix is applied.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. The EPSS score is below 1%, suggesting low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog, implying no widely known exploits. Based on the description, the likely attack requires an attacker to influence the as_rrc module or provide crafted input with sufficient privileges, pointing to a local or privileged attacker scenario. Prompt remediation is advised to mitigate potential denial of service.
OpenCVE Enrichment