CVE-2023-37018: High severity open5gs vulnerability
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a UE Capability Info Indication message missing a required MMEUES1APID field to repeatedly crash the MME, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37018?
CVE-2023-37018 is categorized as a denial of service vulnerability, which can significantly disrupt system availability.
How do I fix CVE-2023-37018?
To mitigate CVE-2023-37018, upgrade to a version of Open5GS MME that is greater than 2.6.4, where this vulnerability is addressed.
What versions of Open5GS MME are affected by CVE-2023-37018?
CVE-2023-37018 affects Open5GS MME versions up to and including 2.6.4.
What type of attack can exploit CVE-2023-37018?
CVE-2023-37018 can be exploited by sending malformed ASN.1 packets over the S1AP interface to repeatedly crash the MME.
What impact does CVE-2023-37018 have on users?
Exploitation of CVE-2023-37018 can lead to denial of service, impairing user access and operation of the Open5GS MME.