CVE-2023-37019: High severity open5gs vulnerability
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an S1Setup Request message missing a required Supported TAs field to repeatedly crash the MME, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37019?
CVE-2023-37019 has been classified as a denial of service vulnerability, allowing remote attackers to crash the MME.
How do I fix CVE-2023-37019?
To mitigate CVE-2023-37019, upgrade Open5GS MME to version 2.6.5 or later, which addresses the vulnerability.
What product is affected by CVE-2023-37019?
CVE-2023-37019 affects Open5GS MME versions up to and including 2.6.4.
What type of attack does CVE-2023-37019 allow?
CVE-2023-37019 allows an attacker to execute a denial of service attack by sending a malformed ASN.1 packet.
Which interface is exploited in CVE-2023-37019?
CVE-2023-37019 exploits the S1AP interface by sending an S1Setup Request message with missing fields.