Impact
The vulnerability is an improper input validation flaw in the NGSetupRequest Handler of Linux Foundation Magma, specifically affecting the NG-IoT-DefaultPagingDRX argument. The flaw allows an attacker to supply crafted input that bypasses the ordinary validation logic, potentially leading to arbitrary code execution or other forms of remote compromise as it does not enforce correct data formats or bounds. This weakness is classified as CWE-20, which denotes improper input validation.
Affected Systems
Linux Foundation Magma version 1.9.0 is affected. No other product versions are listed as vulnerable in the current data.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the exploit is reported as publicly available, meaning the likelihood of exploitation is significant. The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, but the presence of a public exploit indicates that attackers can target the system remotely with relatively low effort. The failure to apply proper input validation opens the path for code execution or other malicious actions depending on the attacker’s execution capabilities. The overall risk level can be considered high for exposed Magma instances until a patch or mitigative measure is applied.
OpenCVE Enrichment