Remote Code Execution Vulnerability in Open5GS MME by Cellular Security
CVE-2023-37018
8.6HIGH
What is CVE-2023-37018?
Open5GS MME versions up to 2.6.4 are susceptible to a vulnerability that allows remote attackers to exploit an assertion failure by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can craft a UE Capability Info Indication
message that omits the necessary MME_UE_S1AP_ID
field. This can lead to repeated crashes of the MME, effectively causing a denial of service and impacting network operations.