CVE-2026-44905
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN.1 decoder accepts the structure as syntactically valid. However, this reveals a logic-based protocol failure where semantic constraints on specific fields are only strictly enforced during OER re-encoding.
Leer descripción completaMostrar menos
Specifically, if a crafted packet contains a certificate where the Psid (Provider Service Identifier) sub-type violates subtype constraints (e.g., out-of-range or invalid CHOICE variant), it is accepted during initial parsing, where subtype constraints are not enforced. Later, when StraightVerifyService attempts to calculate a message hash for cryptographic verification, it must re-encode the signing certificate. The underlying ASN.1 wrapper (asn1c_wrapper.cpp) detects the semantic violation during encoding and raises a std::runtime_error. This exception is not caught within the encoding path and propagates to std::terminate, resulting in immediate process termination. This vulnerability is fixed with commit e1a2e2709210d309458c3d77f98d50dec26c0df0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 % - Impacto principal
T1499Endpoint Denial of Serviceimpact55 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-248
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-44905",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-44905",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-27T13:01:15.575636Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "riebl",
"product": "vanetza",
"versions": [
{
"status": "affected",
"version": "< e1a2e2709210d309458c3d77f98d50dec26c0df0"
},
{
"status": "affected",
"version": "<= 26.02"
}
]
}
]
}
],
"published": "2026-05-26T22:16:43.150",
"references": [
{
"url": "https://github.com/riebl/vanetza/commit/e1a2e2709210d309458c3d77f98d50dec26c0df0",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/riebl/vanetza/security/advisories/GHSA-q9fq-3rx9-7xcv",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/riebl/vanetza/security/advisories/GHSA-q9fq-3rx9-7xcv",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-248"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN.1 decoder accepts the structure as syntactically valid. However, this reveals a logic-based protocol failure where semantic constraints on specific fields are only strictly enforced during OER re-encoding. Specifically, if a crafted packet contains a certificate where the Psid (Provider Service Identifier) sub-type violates subtype constraints (e.g., out-of-range or invalid CHOICE variant), it is accepted during initial parsing, where subtype constraints are not enforced. Later, when StraightVerifyService attempts to calculate a message hash for cryptographic verification, it must re-encode the signing certificate. The underlying ASN.1 wrapper (asn1c_wrapper.cpp) detects the semantic violation during encoding and raises a std::runtime_error. This exception is not caught within the encoding path and propagates to std::terminate, resulting in immediate process termination. This vulnerability is fixed with commit e1a2e2709210d309458c3d77f98d50dec26c0df0."
},
{
"lang": "es",
"value": "Vanetza es una implementación de código abierto de la suite de protocolos ETSI C-ITS. En la versión 26.02 y anteriores, se identificó una vulnerabilidad de denegación de servicio en la cadena de verificación criptográfica de Vanetza. Al procesar mensajes V2X entrantes, el decodificador ASN.1 acepta la estructura como sintácticamente válida. Sin embargo, esto revela un fallo de protocolo basado en lógica donde las restricciones semánticas en campos específicos solo se aplican estrictamente durante la recodificación OER. Específicamente, si un paquete manipulado contiene un certificado donde el subtipo Psid (Identificador de Servicio del Proveedor) viola las restricciones de subtipo (por ejemplo, fuera de rango o variante CHOICE inválida), es aceptado durante el análisis inicial, donde las restricciones de subtipo no se aplican. Más tarde, cuando StraightVerifyService intenta calcular un hash de mensaje para verificación criptográfica, debe recodificar el certificado de firma. El envoltorio ASN.1 subyacente (asn1c_wrapper.cpp) detecta la violación semántica durante la codificación y lanza un std::runtime_error. Esta excepción no es capturada dentro de la ruta de codificación y se propaga a std::terminate, lo que resulta en la terminación inmediata del proceso. Esta vulnerabilidad se corrige con el commit e1a2e2709210d309458c3d77f98d50dec26c0df0."
}
],
"lastModified": "2026-07-24T12:10:00.210",
"sourceIdentifier": "security-advisories@github.com"
}