Denial of Service Vulnerability in Open5GS MME by Open5GS
CVE-2023-37013
7.3HIGH
What is CVE-2023-37013?
Open5GS MME versions up to 2.6.4 contain a vulnerability that allows remote attackers to exploit an assertion through oversized ASN.1 packets over the S1AP interface. By sending multiple large packets, an attacker can trigger the ogs_sctp_recvmsg
routine, leading to an unexpected network state that causes the service to crash, thereby creating a denial of service scenario.