CVE-2024-24451: High severity openairinterface CN5G AMF vulnerability
A stack overflow in the sctpserver::sctpreceiverthread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24451?
CVE-2024-24451 is classified as a high severity vulnerability due to its potential to cause a Denial of Service (DoS) attack.
How do I fix CVE-2024-24451?
To mitigate CVE-2024-24451, upgrade to OpenAirInterface CN5G AMF version 2.0.1 or later, which addresses the stack overflow issue.
What component is affected by CVE-2024-24451?
CVE-2024-24451 affects the sctp_server::sctp_receiver_thread component of the OpenAirInterface CN5G AMF software.
What type of attack can CVE-2024-24451 lead to?
CVE-2024-24451 can lead to a Denial of Service (DoS) attack by allowing attackers to establish repeated SCTP connections.
Which versions of OpenAirInterface CN5G AMF are vulnerable to CVE-2024-24451?
Versions of OpenAirInterface CN5G AMF up to and including v2.0.0 are vulnerable to CVE-2024-24451.