CWE-617— Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.— MITRE CWE catalog
878 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 4 of 18
- CVE-2024-4076HIGHCVSS 7.5EG 7.52024-07-23
Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 th…
- CVE-2023-43529HIGHCVSS 7.5EG 7.52024-05-06
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
- CVE-2024-34475HIGHCVSS 7.5EG 7.52024-05-05
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.
- CVE-2024-31744HIGHCVSS 7.5EG 7.52024-04-19
In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.
- CVE-2024-32475HIGHCVSS 7.5EG 7.52024-04-18
Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer than 255 characters triggers an abnormal termination of Env…
- CVE-2023-33096HIGHCVSS 7.5EG 7.52024-03-04
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
- CVE-2023-33095HIGHCVSS 7.5EG 7.52024-03-04
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.
- CVE-2023-5679HIGHCVSS 7.5EG 7.52024-02-13
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 t…
- CVE-2023-5517HIGHCVSS 7.5EG 7.52024-02-13
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally res…
- CVE-2023-43523HIGHCVSS 7.5EG 7.52024-02-06
Transient DOS while processing 11AZ RTT management action frame received through OTA.
- CVE-2023-34194HIGHCVSS 7.5EG 7.52023-12-13
StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.
- CVE-2023-33044HIGHCVSS 7.5EG 7.52023-12-05
Transient DOS in Data modem while handling TLB control messages from the Network.
- CVE-2023-33043HIGHCVSS 7.5EG 7.52023-12-05
Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.
- CVE-2023-33041HIGHCVSS 7.5EG 7.52023-12-05
Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.
- CVE-2023-49286HIGHCVSS 7.5EG 7.52023-12-04
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. This bug is fixed b…
- CVE-2023-40462HIGHCVSS 7.5EG 7.52023-12-04
The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router func…
- CVE-2023-32846HIGHCVSS 7.5EG 7.52023-12-04
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed…
- CVE-2023-32845HIGHCVSS 7.5EG 7.52023-12-04
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed…
- CVE-2023-32844HIGHCVSS 7.5EG 7.52023-12-04
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed…
- CVE-2023-32843HIGHCVSS 7.5EG 7.52023-12-04
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed…
- CVE-2023-32842HIGHCVSS 7.5EG 7.52023-12-04
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed…
- CVE-2023-32841HIGHCVSS 7.5EG 7.52023-12-04
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed…
- CVE-2023-44175HIGHCVSS 7.5EG 7.52023-10-12
A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows to send specific genuine PIM packets to the device resulting in rpd to crash causing a Denial of Service (Do…
- CVE-2023-24843HIGHCVSS 7.5EG 7.52023-10-03
Transient DOS in Modem while triggering a camping on an 5G cell.
- CVE-2023-32820HIGHCVSS 7.5EG 7.52023-10-02
In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- CVE-2023-4236HIGHCVSS 7.5EG 7.52023-09-20
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query loa…
- CVE-2023-21653HIGHCVSS 7.5EG 7.52023-09-05
Transient DOS in Modem while processing RRC reconfiguration message.
- CVE-2023-21646HIGHCVSS 7.5EG 7.52023-09-05
Transient DOS in Modem while processing invalid System Information Block 1.
- CVE-2023-38976HIGHCVSS 7.5EG 7.52023-08-21
An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.
- CVE-2023-39949HIGHCVSS 7.5EG 7.52023-08-11
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure…
- CVE-2023-39534HIGHCVSS 7.5EG 7.52023-08-11
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Ver…
- CVE-2023-34868HIGHCVSS 7.5EG 7.52023-06-14
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start at jerry-core/parser/js/js-parser-statm.c.
- CVE-2023-34867HIGHCVSS 7.5EG 7.52023-06-14
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at jerry-core/ecma/base/ecma-property-hashmap.c.
- CVE-2023-1428HIGHCVSS 7.5EG 7.52023-06-09
There exists an vulnerability causing an abort() to be called in gRPC. The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x != http, https) grpclb_client_stats: x …
- CVE-2022-40538HIGHCVSS 7.5EG 7.52023-06-06
Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network.
- CVE-2022-33251HIGHCVSS 7.5EG 7.52023-06-06
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
- CVE-2022-22060HIGHCVSS 7.5EG 7.52023-06-06
Assertion occurs while processing Reconfiguration message due to improper validation
- CVE-2023-23759HIGHCVSS 7.5EG 7.52023-05-18
There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second…
- CVE-2023-2156HIGHCVSS 7.5EG 7.52023-05-09
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an …
- CVE-2022-40504HIGHCVSS 7.5EG 7.52023-05-02
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
- CVE-2022-40508HIGHCVSS 7.5EG 7.52023-05-02
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.
- CVE-2022-34144HIGHCVSS 7.5EG 7.52023-05-02
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
- CVE-2022-36440HIGHCVSS 7.5EG 7.52023-04-03
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
- CVE-2023-27789HIGHCVSS 7.5EG 7.52023-03-16
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint.
- CVE-2023-27788HIGHCVSS 7.5EG 7.52023-03-16
An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.
- CVE-2023-27783HIGHCVSS 7.5EG 7.52023-03-16
An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c.
- CVE-2022-40527HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
- CVE-2022-33272HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS in modem due to reachable assertion.
- CVE-2022-33254HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
- CVE-2022-33250HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →