CVE-2024-56921: High severity open5gs vulnerability
An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmmstateexception() function upon receipt of the NausfUEAuthenticationAuthenticate response.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56921?
CVE-2024-56921 has a medium severity rating due to its potential to crash the AMF component.
How do I fix CVE-2024-56921?
To fix CVE-2024-56921, upgrade to Open5gs version 2.7.3 or later, which addresses the issue.
What is the impact of CVE-2024-56921?
CVE-2024-56921 can lead to a denial of service condition by crashing the AMF when specific registration requests are processed.
Who is affected by CVE-2024-56921?
Organizations using Open5gs version 2.7.2 are directly affected by CVE-2024-56921.
What does the gmm_state_exception() function do in CVE-2024-56921?
The gmm_state_exception() function incorrectly handles errors, leading to the AMF crash when processing certain authentication responses.