Denial of Service Vulnerability in Open5GS MME Software
CVE-2023-37012

5.3MEDIUM

Key Information:

Vendor

Open5GS

Status
Vendor
CVE Published:
22 January 2025

What is CVE-2023-37012?

Open5GS MME versions up to 2.6.4 are susceptible to a denial of service vulnerability due to an assertion that can be exploited via a malformed ASN.1 packet sent over the S1AP interface. An attacker can trigger this vulnerability by sending a malformed Initial UE Message that omits the necessary PLMN Identity field. This can lead to continuous crashes of the MME, effectively disrupting service availability and impacting connected users.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-37012 : Denial of Service Vulnerability in Open5GS MME Software