PT-2025-1400 · Open5Gs · Open5Gs Mme

CVE-2023-37008

·

Published

2024-02-02

·

Updated

2025-01-23

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Open5GS MME versions <= 2.6.4
Description The issue is caused by a buffer overflow in the ASN.1 deserialization function of the S1AP handler, leading to type confusion in decoded fields. This results in invalid parsing and freeing of memory, which can cause an MME to crash or potentially allow code execution in certain circumstances.
Recommendations For Open5GS MME versions <= 2.6.4, update to a version greater than 2.6.4 to resolve the issue. As a temporary workaround, consider restricting access to the S1AP handler to minimize the risk of exploitation.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13324
CVE-2023-37008

Affected Products

Open5Gs Mme