CVE-2024-34476: Medium severity open5gs vulnerability
Published May 4, 2024
·Updated
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogsnasencrypt in lib/nas/common/security.c for pkbuf->len.
Affected Software
2 affected components
open5gs open5gs<2.7.1
open5gs open5gs<2.7.1
Event History
May 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 5, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34476?
CVE-2024-34476 is classified as a high severity vulnerability due to the potential for an AMF crash.
2
How do I fix CVE-2024-34476?
To fix CVE-2024-34476, upgrade to Open5GS version 2.7.1 or later.
3
What causes the CVE-2024-34476 vulnerability?
CVE-2024-34476 is caused by a reachable assertion in the ogs_nas_encrypt function when processing specific NAS messages.
4
Which versions of Open5GS are affected by CVE-2024-34476?
Open5GS versions prior to 2.7.1 are affected by CVE-2024-34476.
5
Is there a workaround for CVE-2024-34476?
There is no official workaround for CVE-2024-34476; upgrading to the patched version is recommended.