CVE-2023-37022: High severity open5gs vulnerability
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the UE Context Release Request packet handler. A packet containing an invalid MMEUES1APID field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37022?
CVE-2023-37022 is classified as a denial of service vulnerability due to a reachable assertion in the Open5GS MME.
How do I fix CVE-2023-37022?
To fix CVE-2023-37022, upgrade Open5GS MME to version 2.6.5 or later, which addresses this vulnerability.
What type of attack does CVE-2023-37022 enable?
CVE-2023-37022 enables denial of service attacks by allowing attackers to crash the Open5GS MME through malicious packets.
Which versions of Open5GS MME are affected by CVE-2023-37022?
Open5GS MME versions up to and including 2.6.4 are affected by CVE-2023-37022.
What specific packet causes the issue in CVE-2023-37022?
CVE-2023-37022 is triggered by packets containing an invalid 'MME_UE_S1AP_ID' field.