CVE-2024-24445: Null Pointer Dereference
OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protocol messages which allows an attacker with network-adjacent access to the AMF to carry out denial of service. When a procedure code/presence field tuple is received that is unsupported, OAI indexes into a null function pointer and subsequently dereferences it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24445?
CVE-2024-24445 is classified as a denial of service vulnerability that can severely impact the availability of the OpenAirInterface CN5G AMF.
How do I fix CVE-2024-24445?
To mitigate CVE-2024-24445, upgrade OpenAirInterface CN5G AMF to a version later than 2.0.0 that addresses this vulnerability.
Who is affected by CVE-2024-24445?
All users operating OpenAirInterface CN5G AMF version 2.0.0 or earlier are vulnerable to CVE-2024-24445.
What types of attacks can exploit CVE-2024-24445?
CVE-2024-24445 can be exploited by an attacker with network-adjacent access to send unsupported NGAP protocol messages, resulting in a denial of service.
Is CVE-2024-24445 actively being exploited in the wild?
As of the latest information, there are no confirmed reports of active exploitation of CVE-2024-24445.