First published: Fri Dec 22 2023(Updated: )
An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/free5gc/amf | <=1.2.0 | |
Free5GC | =3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49391 is rated with a critical severity as it allows remote code execution and denial of service.
To mitigate CVE-2023-49391, upgrading to a version of free5GC above 3.3.0 is recommended.
CVE-2023-49391 affects free5GC version 3.3.0 and earlier.
The AMF component of free5GC is vulnerable due to handling of crafted NGAP messages.
Remote attackers can exploit CVE-2023-49391 to execute arbitrary code on vulnerable instances.