CVE-2023-37017
Published: 22 January 2025
Description
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of service.
Security Summary
CVE-2023-37017 is a vulnerability in Open5GS MME versions up to and including 2.6.4, where an assertion failure can be remotely triggered by a malformed ASN.1 packet over the S1AP interface. An attacker can send an S1Setup Request message lacking the required Global eNB ID field, causing the MME to crash. This issue is classified under CWE-617 and carries a CVSS v3.1 base score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).
Any unauthenticated remote attacker with network access to the S1AP interface can exploit this vulnerability. By repeatedly sending the malformed S1Setup Request, the attacker can crash the MME multiple times, resulting in a denial of service that disrupts core network functionality.
For details on advisories and patches, refer to the reference at https://cellularsecurity.org/ransacked.
Details
- CWE(s)