CVE-2024-33382: Medium severity open5gs vulnerability
Published May 8, 2024
·Updated
An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
Affected Software
2 affected components
open5gs open5gs
open5gs open5gs=2.7.0
Event History
May 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33382?
CVE-2024-33382 is classified as a denial of service vulnerability that can impact the availability of Open5GS services.
2
How do I fix CVE-2024-33382?
To address CVE-2024-33382, you should upgrade to the latest version of Open5GS that includes patches for this vulnerability.
3
What are the potential impacts of CVE-2024-33382?
CVE-2024-33382 allows an attacker to cause a denial of service by registering 64 unsuccessful UE/gnb attempts, disrupting network services.
4
Is CVE-2024-33382 present in earlier versions of Open5GS?
Yes, CVE-2024-33382 affects Open5GS version 2.7.0 and may also be present in earlier versions.
5
Who is affected by CVE-2024-33382?
Any organization using Open5GS version 2.7.0 is at risk of CVE-2024-33382 and should take steps to mitigate it.