CVE-2023-37021: High severity open5gs vulnerability
Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a UE Context Modification Failure message missing a required MMEUES1APID field to repeatedly crash the MME, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37021?
CVE-2023-37021 is classified as a high severity vulnerability due to its ability to lead to denial of service.
How do I fix CVE-2023-37021?
To mitigate CVE-2023-37021, upgrade Open5GS MME to version 2.6.5 or later.
What systems are affected by CVE-2023-37021?
CVE-2023-37021 affects Open5GS MME versions up to and including 2.6.4.
Can CVE-2023-37021 be exploited remotely?
Yes, CVE-2023-37021 can be exploited remotely through a malformed ASN.1 packet over the S1AP interface.
What is the potential impact of CVE-2023-37021?
The potential impact of CVE-2023-37021 is that it can lead to repeated crashes of the MME, causing denial of service.