Open5Gs · Open5Gs · CVE-2024-56921
**Name of the Vulnerable Software and Affected Versions**
Open5gs version 2.7.2
**Description**
A problem was discovered in Open5gs where the InitialUEMessage, a registration request sent at a specific time, can cause AMF to crash due to incorrect error handling of the `gmm state exception()` function when receiving the Nausf UEAuthentication Authenticate response.
**Recommendations**
For Open5gs version 2.7.2, consider disabling the `gmm state exception()` function temporarily as a workaround until a patch is available. Restrict access to the InitialUEMessage registration request to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.