PT-2023-29960 · Free5Gc · Free5Gc

Govulnbot

·

Publicado

2023-10-22

·

Atualizado

2024-01-09

·

CVE-2023-46324

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions free5GC udm versions prior to 1.2.0
Description The issue allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.
Recommendations For versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the suci.go module in pkg/suci to minimize the risk of exploitation. Avoid using uncompressed public keys in the affected UDM until the issue is resolved.

Correção

Improper Verification of Cryptographic Signature

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46324
GHSA-CQVV-R3G3-26RF

Produtos afetados

Free5Gc