CVE-2023-4884: Multiple vulnerabilities in Open5GS
Published Oct 3, 2023
·Updated
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.
Affected Software
1 affected component
open5gs open5gs<=2.4.10
Remediation
Information
Open5GS is working on a fix for the reported vulnerabilities.
Event History
Oct 3, 2023
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-4884?
CVE-2023-4884 is a vulnerability in Open5GS that allows an attacker to send an HTTP request and retrieve device information due to the lack of authentication.
2
What is the severity of CVE-2023-4884?
The severity of CVE-2023-4884 is high with a CVSS score of 7.5.
3
How does CVE-2023-4884 affect Open5GS?
CVE-2023-4884 affects Open5GS versions up to and including 2.4.10.
4
How can I fix CVE-2023-4884?
To fix CVE-2023-4884, it is recommended to update Open5GS to a version later than 2.4.10 that addresses the vulnerability.
5
Where can I find more information about CVE-2023-4884?
More information about CVE-2023-4884 can be found at the following reference: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-open5gs