PT-2025-1400 · Open5Gs · Open5Gs Mme

Published

2024-02-02

·

Updated

2025-01-23

·

CVE-2023-37008

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Open5GS MME versions <= 2.6.4
Description The issue is caused by a buffer overflow in the ASN.1 deserialization function of the S1AP handler, leading to type confusion in decoded fields. This results in invalid parsing and freeing of memory, which can cause an MME to crash or potentially allow code execution in certain circumstances.
Recommendations For Open5GS MME versions <= 2.6.4, update to a version greater than 2.6.4 to resolve the issue. As a temporary workaround, consider restricting access to the S1AP handler to minimize the risk of exploitation.

Exploit

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

BDU:2025-13324
CVE-2023-37008

Affected Products

Open5Gs Mme