Magma Mobile Management Entity Reachable Assertion Vulnerability Allowing Denial-of-Service

Vulnerability

A reachable assertion vulnerability has been identified in the Mobile Management Entity (MME) of Magma, affecting versions through 1.8.0. This vulnerability allows remote attackers to crash the MME by sending a NAS packet that includes an 'Emergency Number List' Information Element. The issue arises from an incomplete parsing routine that fails to properly handle the emergency number data, leading to an assertion failure.

Impact

Exploitation of this vulnerability causes a denial-of-service condition by crashing the MME, disrupting cellular communications managed by the MME.

Reproduction

The vulnerability can be reproduced by sending a NAS packet with a malformed 'Emergency Number List' Information Element to the Magma MME. This can be done by an unauthenticated mobile device, without the need for a SIM card, taking advantage of vulnerabilities in the LTE/5G core that allow such packets to be sent over the network.

Remediation

Users can upgrade to Magma version 1.9.0 or later, where this vulnerability has been fixed.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.