CVE-2023-50019: Medium severity open5gs vulnerability
Published Jan 2, 2024
·Updated
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of NudmUECMRegistration response.
Affected Software
1 affected component
open5gs open5gs=2.6.6
Remediation
Patch Available
Event History
Jan 2, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50019?
CVE-2023-50019 has been classified as a high severity vulnerability due to the potential for crashing the AMF module.
2
How do I fix CVE-2023-50019?
To mitigate CVE-2023-50019, upgrading to a version above 2.6.6 that contains the necessary patches is recommended.
3
Which software versions are affected by CVE-2023-50019?
CVE-2023-50019 specifically affects open5gs version 2.6.6.
4
What kind of issue is associated with CVE-2023-50019?
CVE-2023-50019 involves an improper error handling issue that can lead to AMF crashes during specific registration requests.
5
Is there a workaround for CVE-2023-50019 while waiting for a patch?
Currently, there are no documented workarounds for CVE-2023-50019; upgrading is the recommended course of action.