CVE-2023-4882: Multiple vulnerabilities in Open5GS
Published Oct 3, 2023
·Updated
DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the argsassets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.
Affected Software
1 affected component
open5gs open5gs<=2.4.10
Remediation
Information
Open5GS is working on a fix for the reported vulnerabilities.
Event History
Oct 3, 2023
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-4882?
CVE-2023-4882 is a DOS vulnerability in Open5gs that allows an attacker to crash the service by registering a new VNF value.
2
What is the severity of CVE-2023-4882?
CVE-2023-4882 has a severity rating of 7.5, which is considered high.
3
Which software version is affected by CVE-2023-4882?
Open5gs version up to and including 2.4.10 is affected by CVE-2023-4882.
4
What is the impact of CVE-2023-4882?
The impact of CVE-2023-4882 is that it can cause the Open5gs service to crash, leading to a denial of service.
5
Is there a fix available for CVE-2023-4882?
Yes, updating to a version of Open5gs that is higher than 2.4.10 will fix the vulnerability.