CVE-2024-24431: OS Command Injection
Published Nov 15, 2024
·Updated
A reachable assertion in the ogsnasemmdecode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.
Affected Software
2 affected components
open5gs open5gs
open5gs open5gs=2.7.0
Event History
Nov 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24431?
CVE-2024-24431 has a high severity rating due to its potential to cause a Denial of Service (DoS).
2
What vulnerability does CVE-2024-24431 address?
CVE-2024-24431 addresses a reachable assertion in the ogs_nas_emm_decode function in Open5GS v2.7.0.
3
How do I fix CVE-2024-24431?
To fix CVE-2024-24431, upgrade to a version of Open5GS that addresses this vulnerability.
4
What kind of attack is possible with CVE-2024-24431?
CVE-2024-24431 allows attackers to cause a Denial of Service by sending a crafted NAS packet with a zero-length EMM message length.
5
Which version of Open5GS is affected by CVE-2024-24431?
Open5GS version 2.7.0 is affected by CVE-2024-24431.