Denial of Service Vulnerability in Open5GS MME by Cellular Security
CVE-2023-37020
8.6HIGH
What is CVE-2023-37020?
The Open5GS MME component in versions prior to 2.6.4 has a significant vulnerability that allows remote attackers to trigger an assertion failure by sending malformed ASN.1 packets over the S1AP interface. By exploiting this vulnerability with a specifically crafted 'UE Context Release Complete' message that omits the mandatory 'MME_UE_S1AP_ID' field, an attacker can cause the MME to crash repeatedly, leading to disruptions in service availability. It is crucial for users of affected versions to update to mitigate this risk.