Back to overview

CVE-2025-55398

CRITICAL
9.8
CVSS 3.1
Description
An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed Encoding Rules), asn1c-generated decoders fail to enforce INTEGER constraints when the bound is positive and exceeds 32 bits in length, potentially allowing incorrect or malicious input to be processed.

Metadata

CVE ID
CVE-2025-55398
State
PUBLISHED
Assigner
mitre
Reserved
2025-08-13 00:00 UTC
Published
2025-08-22 00:00 UTC
Last updated
2025-08-26 14:07 UTC
Primary CWE
CWE-1284
CWE-1284 Improper Validation of Specified Quantity in Input
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-1284 adp CWE-1284 Improper Validation of Specified Quantity in Input
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview