CVE-2023-49391: Code Injection
Published Dec 22, 2023
·Updated
An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.
Affected Software
2 affected components
go/github.com/free5gc/amf<=1.2.0
free5gc Free5gc=3.3.0
Event History
Dec 22, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
12:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-49391?
CVE-2023-49391 is rated with a critical severity as it allows remote code execution and denial of service.
2
How do I fix CVE-2023-49391?
To mitigate CVE-2023-49391, upgrading to a version of free5GC above 3.3.0 is recommended.
3
Which versions of free5GC are affected by CVE-2023-49391?
CVE-2023-49391 affects free5GC version 3.3.0 and earlier.
4
What component of free5GC is vulnerable in CVE-2023-49391?
The AMF component of free5GC is vulnerable due to handling of crafted NGAP messages.
5
Who can exploit CVE-2023-49391?
Remote attackers can exploit CVE-2023-49391 to execute arbitrary code on vulnerable instances.