CVE-2021-45462: High severity open5gs vulnerability
Published Dec 23, 2021
·Updated
In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
Affected Software
1 affected component
open5gs open5gs=2.4.0
Remediation
Event History
Dec 23, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-45462.
2
What is the severity of CVE-2021-45462?
The severity of CVE-2021-45462 is high with a score of 7.5.
3
How does CVE-2021-45462 affect Open5GS?
CVE-2021-45462 affects Open5GS version 2.4.0.
4
How can CVE-2021-45462 be exploited?
CVE-2021-45462 can be exploited by sending a crafted packet from a UE (User Equipment) that can crash the SGW-U/UPF (Serving Gateway-Ultimate Packet Forwarding).
5
Are there any references related to CVE-2021-45462?
Yes, you can find references related to CVE-2021-45462 at the following links: [link1](https://github.com/open5gs/open5gs/commit/a0f2535cb5a29bba6dbbccdb90c74ccd770cc700), [link2](https://www.trendmicro.com/en_us/research/23/i/attacks-on-5g-infrastructure-from-users-devices.html).