Denial of Service Vulnerability in Open5GS MME by Open5GS
CVE-2023-37007
5.3MEDIUM
What is CVE-2023-37007?
Open5GS MME versions 2.6.4 and earlier are susceptible to a denial of service vulnerability that can be exploited remotely. An attacker can trigger an assertion failure by sending a malformed ASN.1 packet through the S1AP interface, specifically using a Handover Cancel
message that omits the required MME_UE_S1AP_ID
field. This manipulation can cause the MME to crash repeatedly, leading to a denial of service condition, severely affecting system availability.