PT-2022-24601 · Free5Gc · Free5Gc

P1-Bmuo

·

Published

2022-11-18

·

Updated

2022-11-24

·

CVE-2022-38871

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Free5gc version 3.0.5
Description The issue arises due to malformed NAS messages, causing the AMF to break.
Recommendations For Free5gc version 3.0.5, consider implementing input validation to handle malformed NAS messages properly until a patch is available.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2022-38871
GHSA-M74X-FXJH-3QH9

Affected Products

Free5Gc