PT-2021-24241 · Open5Gs · Open5Gs
Salim S.I
·
Published
2021-12-23
·
Updated
2023-09-25
·
CVE-2021-45462
CVSS v3.1
7.5
High
| Vector | AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions:
Open5GS version 2.4.0
Description:
A crafted packet from a UE can cause a crash in the SGW-U/UPF component. This issue can potentially be used to deploy a denial-of-service (DoS) attack on private 5G networks.
Recommendations:
For Open5GS version 2.4.0, consider implementing packet validation and filtering to prevent malicious packets from reaching the SGW-U/UPF component. As a temporary workaround, restrict access to the SGW-U/UPF component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open5Gs