Denial of Service Vulnerability in Open5GS MME by Open5GS
CVE-2023-37019
8.6HIGH
What is CVE-2023-37019?
The Open5GS MME contains a vulnerability that allows an attacker to exploit an assertion via a malformed ASN.1 packet sent over the S1AP interface. By sending an S1Setup Request
message that lacks the necessary Supported TAs
field, an attacker can trigger a condition that leads to repeated crashes of the MME, thereby causing a denial of service. This issue poses significant risks to network availability and requires prompt remediation.