In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highl
On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the devic
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if
Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it
Uncaught exception in OpenBMC Firmware for the Intel(R) Server M50FCP Family and Intel(R) Server D50DNP Family before ve
Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Emai
An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 l
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced
tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 1
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi
@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the
A denial-of-service security issue in the affected product. The security issue stems from a fault occurring when a craft
A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed
Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may af
ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) s
Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that i
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote
Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent
Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway
Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the lib
badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacke
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malforme
Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0
In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could
A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent a
Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may a
Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerabilit
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.
StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (D
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnera
Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the
Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an au
Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially ena
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information
Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affec
Uncaught exception for some Intel(R) CST software before version 8.7.10803 may allow an authenticated user to potentiall
Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is presen
Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of thi
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmente
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially cra
Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over f
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information
Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may al
An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment pro
Frequently Asked Questions
What is CWE-248?
CWE-248 (CWE-248) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-248?
There are 271 CVE records associated with CWE-248 in our database. Of these, 3 are critical severity, 125 are high severity, and 112 are medium severity.
How can I protect against CWE-248 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-248 using AI-powered security agents.
Detect CWE-248 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-248 vulnerabilities across your infrastructure.
Get Started