Magma
cpe:2.3:a:linuxfoundation:magma:*:*:*:*:*:*:*
- <= 1.8.0
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) component of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'Uplink NAS Transport' packet that lacks the required 'ENB_UE_S1AP_ID' field.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the MME to crash and disrupt all cellular communications managed by that MME.
To reproduce this vulnerability, send an S1AP 'Uplink NAS Transport' packet to the Magma MME that is missing the 'ENB_UE_S1AP_ID' field. This can be done by an unauthenticated mobile device or, over the internet, by exploiting a vulnerability in the cellular core.
Users can upgrade to Magma version 1.9 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.