CVE-2024-24450: Buffer Overflow
Stack-based memcpy buffer overflow in the ngaphandlepdusessionresourcesetupresponse routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response with a suffciently large FailedToSetupList IE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24450?
CVE-2024-24450 has been classified as a high severity vulnerability due to the potential for denial of service and remote code execution.
How do I fix CVE-2024-24450?
To fix CVE-2024-24450, upgrade to OpenAirInterface CN5G AMF version 2.0.1 or later, which addresses the buffer overflow issue.
Who is affected by CVE-2024-24450?
CVE-2024-24450 affects all versions of OpenAirInterface CN5G AMF up to and including 2.0.0 that utilize the N2 interface.
What type of attack can exploit CVE-2024-24450?
An attacker can exploit CVE-2024-24450 by sending specially crafted messages on the N2 interface to trigger a stack-based buffer overflow.
What are the potential consequences of CVE-2024-24450?
The consequences of CVE-2024-24450 include possible denial of service attacks against the AMF and the potential for remote code execution.