CVE-2023-37002: Medium severity open5gs vulnerability
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an E-RAB Modification Indication message missing a required MMEUES1APID field to repeatedly crash the MME, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37002?
CVE-2023-37002 has been classified as a high severity vulnerability due to its ability to cause denial of service.
How do I fix CVE-2023-37002?
To mitigate CVE-2023-37002, upgrade Open5GS MME to version 2.6.5 or later.
What software is affected by CVE-2023-37002?
CVE-2023-37002 affects Open5GS MME versions 2.6.4 and earlier.
What type of attack does CVE-2023-37002 enable?
CVE-2023-37002 allows an attacker to crash the MME by sending a malformed ASN.1 packet.
How can the impact of CVE-2023-37002 be assessed?
The impact of CVE-2023-37002 can be assessed by evaluating the availability of the Open5GS MME service in your environment.