CVE-2024-24444: High severity openairinterface CN5G AMF vulnerability
Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24444?
CVE-2024-24444 is classified as a high severity vulnerability due to its potential to cause Denial of Service (DoS) attacks.
How does CVE-2024-24444 affect OpenAirInterface CN5G AMF?
CVE-2024-24444 allows attackers to exploit improper file descriptor handling for closed connections, leading to DoS by overwhelming the N2 interface with SCTP connection attempts.
How do I fix CVE-2024-24444?
To mitigate CVE-2024-24444, upgrade OpenAirInterface CN5G AMF to version 2.0.1 or later, where the vulnerability is addressed.
What versions of OpenAirInterface CN5G AMF are affected by CVE-2024-24444?
CVE-2024-24444 affects OpenAirInterface CN5G AMF versions up to and including 2.0.0.
What can happen if CVE-2024-24444 is exploited?
If exploited, CVE-2024-24444 can lead to service outages by crippling the N2 interface through repeated SCTP connection requests.