PT-2025-2377 · Open5Gs · Open5Gs

Published

2025-01-21

·

Updated

2025-01-22

·

CVE-2024-24428

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Open5GS versions 2.6.4 and earlier
Description: A reachable assertion in the oai nas 5gmm decode function allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.
Recommendations: For Open5GS versions 2.6.4 and earlier, consider disabling the oai nas 5gmm decode function until a patch is available to prevent Denial of Service (DoS) attacks via crafted NGAP packets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Assertion Failure

Weakness Enumeration

Related Identifiers

CVE-2024-24428

Affected Products

Open5Gs