CWE-240Base

Improper Handling of Inconsistent Structural Elements

Draft in the CWE catalog · 4 CVEs mapped

4
CVEs mapped
7.5
Median CVSS
What it is

The product does not handle or incorrectly handles when two or more structural elements should be consistent, but are not.

Recent examples
7.1cvss
CVE-2025-4321

DoS in RS9116W-WiSeConnect L2CAP protocol due to reception of malformed packets

In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device to normal operation

HIGHno explanation yet
0%
epss
7.5cvss
CVE-2023-39915

Crashes on parsing certain invalid RPKI objects

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.

HIGHno explanation yet
1%
epss
7.5cvss
CVE-2023-39914

BER/CER/DER decoder panics on invalid input

NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-240
Abstraction
Base
Structure
Simple
Status
Draft