ZeroHour

CVE-2023-37008

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p21
Published
()
Modified
Description

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in certain circumstances.

Vendors
open5gs
Products
open5gs
Weakness
CWE-617
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.