PT-2023-6922 · Free5Gc · Free5Gc

Tjbdlqo

·

Published

2023-11-15

·

Updated

2023-11-21

·

CVE-2023-47345

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions free5gc version 3.3.0
Description The issue is related to incorrect clearance or release of resources in the free5gc software, which is used for organizing mobile networks of the 5th generation (5G). This can be exploited by a remote attacker using a specially crafted PFCP message, potentially leading to a denial of service. Specifically, the vulnerability involves a buffer overflow that can be triggered by a crafted PFCP message with a malformed PFCP Heartbeat message, where the Recovery Time Stamp IE length is mutated to zero.
Recommendations For free5gc version 3.3.0, consider disabling the handling of PFCP Heartbeat messages until a patch is available to prevent the buffer overflow. Additionally, restrict access to the PFCP interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07940
CVE-2023-47345
GHSA-6944-6PMV-6MP2

Affected Products

Free5Gc