PT-2024-25927 · Open5Gs · Open5Gs

Acetcom

·

Published

2024-05-04

·

Updated

2025-04-22

·

CVE-2024-34476

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.7.1
Description The issue is related to a reachable assertion that can cause an AMF crash via NAS messages from a UE. This occurs due to improper handling of the pkbuf->len variable in the ogs nas encrypt function located in lib/nas/common/security.c.
Recommendations For versions prior to 2.7.1, upgrade to version 2.7.1 or later to resolve the issue. As a temporary workaround, consider restricting the handling of NAS messages from UEs to minimize the risk of exploitation. Audit the code for similar issues related to improper length handling to prevent future vulnerabilities.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-34476

Affected Products

Open5Gs