Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-35215", "assignerOrgId": "dbe78b00-5e7b-4fda-8748-329789ecfc5c", "state": "PUBLISHED", "assignerShortName": "blackberry", "dateReserved": "2024-05-13T21:20:04.328Z", "datePublished": "2024-10-08T17:35:57.156Z", "dateUpdated": "2024-10-08T18:36:04.799Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "unaffected", "product": "QNX Software Development Platform (SDP)", "vendor": "BlackBerry", "versions": [{"status": "affected", "version": "7.1 and 7.0"}]}], "datePublic": "2024-10-08T17:35:00.000Z", "descriptions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "<span style=\"background-color: rgb(255, 255, 255);\">NULL pointer dereference in IP socket options processing of the Networking Stack </span><span style=\"background-color: rgb(255, 255, 255);\">in</span><span style=\"background-color: rgb(255, 255, 255);\"> QNX </span><span style=\"background-color: rgb(255, 255, 255);\">Software </span><span style=\"background-color: rgb(255, 255, 255);\">Development</span><span style=\"background-color: rgb(255, 255, 255);\"> Platform (</span><span style=\"background-color: rgb(255, 255, 255);\">SDP</span><span style=\"background-color: rgb(255, 255, 255);\">)</span><span style=\"background-color: rgb(255, 255, 255);\"> version(s) 7.</span><span style=\"background-color: rgb(255, 255, 255);\">1</span><span style=\"background-color: rgb(255, 255, 255);\"> and 7.</span><span style=\"background-color: rgb(255, 255, 255);\">0</span><span style=\"background-color: rgb(255, 255, 255);\"> could allow an attacker </span><span style=\"background-color: rgb(255, 255, 255);\">with local access</span><span style=\"background-color: rgb(255, 255, 255);\"> to cause a </span><span style=\"background-color: rgb(255, 255, 255);\">d</span><span style=\"background-color: rgb(255, 255, 255);\">enial-of-</span><span style=\"background-color: rgb(255, 255, 255);\">s</span><span style=\"background-color: rgb(255, 255, 255);\">ervice condition in the context of the </span><span style=\"background-color: rgb(255, 255, 255);\">N</span><span style=\"background-color: rgb(255, 255, 255);\">etworking </span><span style=\"background-color: rgb(255, 255, 255);\">S</span><span style=\"background-color: rgb(255, 255, 255);\">tack</span><span style=\"background-color: rgb(255, 255, 255);\"> process</span><span style=\"background-color: rgb(255, 255, 255);\">.</span><br>"}], "value": "NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process."}], "impacts": [{"capecId": "CAPEC-549", "descriptions": [{"lang": "en", "value": "CAPEC-549 Local Execution of Code"}]}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 6.2, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1"}, "format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "problemTypes": [{"descriptions": [{"cweId": "CWE-476", "description": "CWE-476 NULL Pointer Dereference", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"orgId": "dbe78b00-5e7b-4fda-8748-329789ecfc5c", "shortName": "blackberry", "dateUpdated": "2024-10-08T17:35:57.156Z"}, "references": [{"url": "https://support.blackberry.com/pkb/s/article/140162"}], "source": {"discovery": "UNKNOWN"}, "x_generator": {"engine": "Vulnogram 0.2.0"}}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-10-08T18:35:30.013530Z", "id": "CVE-2024-35215", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-10-08T18:36:04.799Z"}}]}}