Impact
a flaw in the SecurityModeComplete Handler allows an attacker to manipulate the integrity check value, bypassing the component’s validation of incoming data. This improper validation can enable the attacker to perform unauthorized actions, potentially compromising system confidentiality, integrity, or availability. The weakness is captured by CWE‑345 (Information Disclosure) and CWE‑354 (Improper Validation).
Affected Systems
All installations of Linux Foundation Magma version 1.9.0 that have not applied the vendor’s fix are vulnerable. The component is part of the core Magma control plane and is used by operators building mobile network functions.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating a moderate to high severity. The EPSS score is not available, but the exploit is publicly documented and may be used. It is not listed in CISA’s KEV catalog, although the presence of a public exploit raises concern. Attackers can launch the exploit remotely, and the risk of exploitation is therefore non‑negligible.
OpenCVE Enrichment