CVE-2023-37013: High severity open5gs vulnerability
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the ogssctprecvmsg routine to reach an unexpected network state and crash, leading to denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37013?
CVE-2023-37013 has been assigned a critical severity due to its potential to cause a denial of service when exploited.
How do I fix CVE-2023-37013?
To fix CVE-2023-37013, users should upgrade Open5GS MME to versions later than 2.6.4 where the vulnerability is addressed.
What type of attack does CVE-2023-37013 enable?
CVE-2023-37013 enables a remote denial of service attack via oversized ASN.1 packets sent over the S1AP interface.
Which versions of Open5GS MME are affected by CVE-2023-37013?
Open5GS MME versions up to and including 2.6.4 are affected by CVE-2023-37013.
What component is primarily affected in CVE-2023-37013?
The primary component affected in CVE-2023-37013 is the `ogs_sctp_recvmsg` routine in Open5GS MME.