Buffer Overflow Vulnerability in Open5GS MME by Open5GS
CVE-2023-37008
5.3MEDIUM
What is CVE-2023-37008?
Open5GS MME, particularly versions up to 2.6.4, is susceptible to a buffer overflow vulnerability within the ASN.1 deserialization functionality of its S1AP handler. This flaw can result in type confusion during the decoding process, potentially allowing for improper memory management—leading to the unexpected freeing of memory. An attacker could exploit this vulnerability to crash the MME or, under certain conditions, execute arbitrary code, posing a significant risk to the integrity and availability of the affected system.