Remote Denial of Service Vulnerability in Open5GS MME by Cellular Security
CVE-2023-37009
6.3MEDIUM
What is CVE-2023-37009?
Open5GS MME versions up to 2.6.4 are vulnerable to a denial of service attack due to an assertion that can be exploited via a malformed ASN.1 packet. An attacker can send a 'Handover Notification' message omitting the essential 'MME_UE_S1AP_ID' field, causing the MME to crash repeatedly. This vulnerability primarily affects the S1AP interface, leaving systems susceptible to interruptions and downtime.