Impact
A vulnerability exists in the InitialUEMessage handler of Linux Foundation Magma version 1.9.0 that allows remote attackers to read sensitive internal data. The flaw stems from an unknown function that mishandles incoming messages and can reveal confidential information, mapping to CWE-200 and CWE-284. Because the disclosure can occur without authenticated access, it poses a confidentiality risk to users relying on Magma for network control.
Affected Systems
The affected product is Linux Foundation Magma, specifically version 1.9.0. No other versions are explicitly listed as vulnerable in the data, so the impact is confined to installations running that release.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity; the EPSS score is unavailable, but the vulnerability is publicly disclosed, meaning the exploit appears on open source channels. Attackers can initiate the exploit remotely, likely via the control plane interface. Although the vulnerability is not yet listed in CISA KeV, the remote origin and lack of authentication control elevate the operational risk for exposed environments.
OpenCVE Enrichment