PT-2025-1414 · Open5Gs · Open5Gs
Publicado
2025-01-22
·
Atualizado
2025-01-27
·
CVE-2023-37022
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Open5GS MME versions <= 2.6.4
Description
The issue is related to a reachable assertion in the
UE Context Release Request packet handler. A packet containing an invalid MME UE S1AP ID field causes Open5GS to crash. An attacker may repeatedly send such packets to cause denial of service.Recommendations
For Open5GS MME versions <= 2.6.4, consider updating to a version greater than 2.6.4 to resolve the issue. As a temporary workaround, restrict access to the
UE Context Release Request packet handler to minimize the risk of exploitation. Avoid sending packets with invalid MME UE S1AP ID fields to prevent denial of service.Exploit
Correção
Allocation of Resources Without Limits
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Open5Gs