Denial of Service Vulnerability in Magma by Cellular Security
CVE-2024-24424

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
21 January 2025

What is CVE-2024-24424?

A vulnerability has been identified in the decode_access_point_name_ie function of Magma versions up to 1.8.0, which can be exploited by attackers to trigger a Denial of Service (DoS). This occurs via the transmission of specially crafted NAS (Network Access Server) packets that can lead to unexpected behavior, effectively disrupting service availability. A patch has been introduced in version 1.9 to address this issue, underscoring the importance of updating to the latest version for enhanced security and stability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.