Vulnerabilities > CVE-2023-31441 - NULL Pointer Dereference vulnerability in Ncia Advisor Network

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
ncia
CWE-476

Summary

In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafted JSON file to sanitizeJson and cause an exception. This is related to the U+FFFD Unicode replacement character. A for loop does not consider that a data structure is being modified during loop execution.

Vulnerable Configurations

Part Description Count
Application
Ncia
137

Common Weakness Enumeration (CWE)