Denial of Service Vulnerability in Open5GS MME Software
CVE-2023-37012
5.3MEDIUM
What is CVE-2023-37012?
Open5GS MME versions up to 2.6.4 are susceptible to a denial of service vulnerability due to an assertion that can be exploited via a malformed ASN.1 packet sent over the S1AP interface. An attacker can trigger this vulnerability by sending a malformed Initial UE Message
that omits the necessary PLMN Identity
field. This can lead to continuous crashes of the MME, effectively disrupting service availability and impacting connected users.