Magma Mobile Management Entity Null Pointer Dereference Vulnerability via Malformed S1AP S1Setup Request Packet

Vulnerability

A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP S1Setup Request packet that omits the required Global eNB ID field. The issue has been fixed in Magma version 1.9.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the MME to crash and disrupt all cellular communications managed by that MME.

Reproduction

To reproduce this vulnerability, send an S1AP S1Setup Request packet to the Magma MME that is missing the Global eNB ID field. This can be done by an unauthenticated mobile device or over the Internet, taking advantage of Wi-Fi Calling services.

Remediation

Users can upgrade to Magma version 1.9 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.