CVE-2024-34475: High severity open5gs vulnerability
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmmstateauthentication in amf/gmm-sm.c for != OGSERROR.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34475?
CVE-2024-34475 is classified as a high severity vulnerability because it can lead to an AMF crash, impacting the availability of the Open5GS service.
How do I fix CVE-2024-34475?
To fix CVE-2024-34475, you should upgrade Open5GS to version 2.7.1 or later, where the vulnerability has been addressed.
What causes the CVE-2024-34475 vulnerability?
CVE-2024-34475 is caused by a reachable assertion in the Open5GS implementation, triggered by specific NAS messages from a User Equipment (UE).
What software versions are affected by CVE-2024-34475?
CVE-2024-34475 affects Open5GS versions prior to 2.7.1.
What impact does CVE-2024-34475 have on systems running Open5GS?
The impact of CVE-2024-34475 is significant, as it can lead to service disruptions when the AMF crashes due to the vulnerability.