Magma
cpe:2.3:a:linuxfoundation:magma:*:*:*:*:*:*:*
- <= 1.8.0
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP Initial UE Message packet that omits the required EUTRAN_CGI field.
Exploitation of this vulnerability causes a denial-of-service condition by crashing the MME, disrupting all cellular communications managed by that entity.
To reproduce this vulnerability, send an S1AP Initial UE Message packet to the MME that is missing the EUTRAN_CGI field. This can be done by an unauthenticated mobile device or, with base station access, by manipulating the packet before it reaches the MME.
Users can upgrade to Magma version 1.9 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.