Inaccurate Frame Deduplication in ChirpStack Network Server Affects LoRa Gateways
CVE-2020-28349
6.5MEDIUM
What is CVE-2020-28349?
An issue in ChirpStack Network Server 3.9.0 related to an inaccurate frame deduplication process allows a malicious gateway to execute an uplink Denial of Service attack. This occurs when malformed frequency attributes are processed by the CollectAndCallOnceCollect function in internal/uplink/collect.go. The ChirpStack team has indicated that using untrusted LoRa gateways poses significant risks, contributing to potential security challenges within the network.
