Open5GS MME Assertion Failure Vulnerability in S1AP Interface Allowing Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in Open5GS MME versions through 2.6.4. The issue arises from an assertion failure that can be remotely triggered by sending a malformed ASN.1 packet over the S1AP interface. Specifically, an attacker can send an 'S1Setup Request' message that omits the required 'Supported TAs' field, causing the MME to crash. This vulnerability disrupts cellular communications and could persist until network operators apply a patch.

Impact

Exploitation of this vulnerability causes the Open5GS MME to crash, disrupting all cellular communications managed by the MME, including voice calls, messaging, and data services. This denial-of-service condition could persist for an extended period, potentially causing widespread disruption in the affected area.

Reproduction

To reproduce this vulnerability, send an 'S1Setup Request' message over the S1AP interface that lacks the 'Supported TAs' field. This can be done by an unauthenticated mobile device or, due to Wi-Fi Calling services, by any entity on the Internet.

Remediation

Users can upgrade to Open5GS version 2.7.0 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.