CVE-2024-24449: Medium severity openairinterface vulnerability
Published Nov 15, 2024
·Updated
An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.
Affected Software
1 affected component
openairinterface CN5G AMF<2.0.0
Event History
Nov 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-24449?
CVE-2024-24449 is classified as a Denial of Service vulnerability due to an uninitialized pointer dereference.
2
How do I fix CVE-2024-24449?
To fix CVE-2024-24449, upgrade to a version of OpenAirInterface CN5G AMF that is higher than v2.0.0.
3
What component is affected by CVE-2024-24449?
CVE-2024-24449 affects the NasPdu::NasPdu component of OpenAirInterface CN5G AMF.
4
What type of attack is possible with CVE-2024-24449?
CVE-2024-24449 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage.
5
Which versions of OpenAirInterface are vulnerable to CVE-2024-24449?
OpenAirInterface CN5G AMF versions up to and including v2.0.0 are vulnerable to CVE-2024-24449.