CVE-2023-37016: High severity open5gs vulnerability
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a UE Context Modification Response message missing a required MMEUES1APID field to repeatedly crash the MME, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37016?
CVE-2023-37016 has been classified as a high severity vulnerability due to its potential for denial of service attacks.
How do I fix CVE-2023-37016?
To remediate CVE-2023-37016, upgrade Open5GS MME to version 2.6.5 or later.
What systems are affected by CVE-2023-37016?
CVE-2023-37016 affects Open5GS MME versions up to and including 2.6.4.
Can CVE-2023-37016 be exploited remotely?
Yes, CVE-2023-37016 can be exploited remotely through the S1AP interface by sending a malformed ASN.1 packet.
What impact does CVE-2023-37016 have?
CVE-2023-37016 can cause the MME to crash, leading to a denial of service for legitimate users.