CVE-2023-37008

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in certain circumstances.
References
Link Resource
https://cellularsecurity.org/ransacked Third Party Advisory Exploit Technical Description
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-22 15:15

Updated : 2025-04-22 17:14


NVD link : CVE-2023-37008

Mitre link : CVE-2023-37008

CVE.ORG link : CVE-2023-37008


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-617

Reachable Assertion