CVE-2023-47347: Buffer Overflow
Published Nov 15, 2023
·Updated
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.
Affected Software
1 affected component
free5gc Free5gc=3.3.0
Event History
Nov 15, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-47347.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.'
3
What is the affected software?
The affected software is Free5gc version 3.3.0.
4
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 7.5.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by sending crafted PFCP messages with a mutated Sequence Number, causing a buffer overflow and resulting in a denial of service.