Buffer Overflow Vulnerability in Open5GS Diameter Rx Handler
CVE-2024-14044
Key Information:
Badges
What is CVE-2024-14044?
A buffer overflow vulnerability exists in the Diameter Rx Handler of Open5GS due to improper handling of arguments in the pcrf_rx_aar_cb function. This issue enables a remote attacker to exploit the vulnerability by manipulating the num_of_media_component/num_of_sub parameters. Successful exploitation may lead to memory corruption, potentially allowing unauthorized access or system instability. Users are strongly advised to upgrade to version 2.7.2 to mitigate this security risk.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
