Buffer Overflow Vulnerability in Open5GS MME by Open5GS
CVE-2023-37008

5.3MEDIUM

Key Information:

Vendor

Open5GS

Vendor
CVE Published:
22 January 2025

What is CVE-2023-37008?

Open5GS MME, particularly versions up to 2.6.4, is susceptible to a buffer overflow vulnerability within the ASN.1 deserialization functionality of its S1AP handler. This flaw can result in type confusion during the decoding process, potentially allowing for improper memory management—leading to the unexpected freeing of memory. An attacker could exploit this vulnerability to crash the MME or, under certain conditions, execute arbitrary code, posing a significant risk to the integrity and availability of the affected system.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-37008 : Buffer Overflow Vulnerability in Open5GS MME by Open5GS