Magma
cpe:2.3:a:linuxfoundation:magma:*:*:*:*:*:*:*
- <= 1.8.0
A reachable assertion vulnerability has been identified in the Mobile Management Entity (MME) of Magma, affecting versions through 1.8.0. This vulnerability allows remote attackers to crash the MME by sending a NAS packet that includes an 'Emergency Number List' Information Element. The issue arises from an incomplete parsing routine that fails to properly handle the emergency number data, leading to an assertion failure.
Exploitation of this vulnerability causes a denial-of-service condition by crashing the MME, disrupting cellular communications managed by the MME.
The vulnerability can be reproduced by sending a NAS packet with a malformed 'Emergency Number List' Information Element to the Magma MME. This can be done by an unauthenticated mobile device, without the need for a SIM card, taking advantage of vulnerabilities in the LTE/5G core that allow such packets to be sent over the network.
Users can upgrade to Magma version 1.9.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.