Open5GS MME
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*
- <= 2.6.4
A buffer overflow vulnerability has been identified in Open5GS MME versions through 2.6.4. This issue arises from an improper handling of ASN.1 packets on the S1AP interface, specifically in the processing of 'Handover Required' messages that lack a mandatory 'MME_UE_S1AP_ID' field. The vulnerability can be exploited remotely, leading to a denial-of-service condition by causing the MME to crash. This disruption can persist until the vulnerability is patched.
Exploitation of this vulnerability causes a stack-based buffer overflow, leading to a crash of the Open5GS MME. This disruption can persist until network operators apply the necessary patch.
To reproduce this vulnerability, send a 'Handover Required' message over the S1AP interface that omits the 'MME_UE_S1AP_ID' field. This can be done by establishing a connection to the MME and transmitting the crafted message, which will trigger the buffer overflow by exploiting the absence of the required identifier.
Users can upgrade to Open5GS version 2.7.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.