CVE-2023-37008

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in certain circumstances.
References
Link Resource
https://cellularsecurity.org/ransacked Exploit Technical Description Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-22 15:15

Updated : 2025-04-22 17:14


NVD link : CVE-2023-37008

Mitre link : CVE-2023-37008

CVE.ORG link : CVE-2023-37008


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-617

Reachable Assertion