7.4
CVE-2026-42800
- EPSS 0.24%
- Veröffentlicht 30.04.2026 08:52:01
- Zuletzt bearbeitet 05.05.2026 02:54:21
- Quelle 68630edc-a58c-4cbd-9b01-0e1304
- CVE-Watchlists
- Unerledigt
Deference after null check in ims_client sip
NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asrmicro ≫ Asr1901 Firmware Version < 1.225.003
Asrmicro ≫ Asr1903 Firmware Version < 1.225.003
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.145 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
| 68630edc-a58c-4cbd-9b01-0e130455c8ae | 7.4 | 3.1 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://www.asrmicro.com/en/goods/psirt?cid=44