PT-2024-20396 · Unknown · Openairinterface Cn5G Amf

CVE-2024-24446

·

Published

2024-11-15

·

Updated

2024-11-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenAirInterface CN5G AMF versions up to 2.0.0
Description The issue is caused by an uninitialized pointer dereference, allowing attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF.
Recommendations For OpenAirInterface CN5G AMF versions up to 2.0.0, update to a version later than 2.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the AMF to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-24446

Affected Products

Openairinterface Cn5G Amf