Magma
cpe:2.3:a:linuxfoundation:magma:*:*:*:*:*:*:*
- <= 1.8.0
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP Initial UE Message packet that omits the required TAI field. The issue has been addressed in Magma version 1.9.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the MME to crash and disrupt cellular communications managed by the MME.
To reproduce this vulnerability, send an S1AP Initial UE Message packet to the Magma MME that is missing the TAI field. This can be done by an unauthenticated mobile device or, due to the deployment of Wi-Fi Calling services, from any entity on the Internet.
Users can upgrade to Magma version 1.9 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.