Impact
The Ref::SignalGen component of the fprime framework v4.2.2 performs no validation on user‑controlled parameters, allowing an attacker to supply unsafe values that trigger a denial of service. The weakness is the result of improper input validation, leading to uncontrolled resource usage or a fatal error within the component.
Affected Systems
The vulnerability exists in fprime framework version 4.2.2, specifically within the Ref::SignalGen component. No other versions or vendor products are currently known to be affected.
Risk and Exploitability
The EPSS score is listed as less than 1%, indicating a very low but nonzero probability of exploitation. The CVSS score of 7.5 reflects moderate to high severity. The vulnerability is not listed in the CISA KEV catalog, and no documented public exploits exist at present. Attackers would need to provide crafted parameters to the SignalGen component; based on the description, it is inferred that such parameters can be supplied by a user with access to the component. However, specific external attack vectors are not detailed in the advisory.
OpenCVE Enrichment