The Linux Foundation Magma
cpe:2.3:a:linuxfoundation:magma:*:*:*:*:*:*:*
- <= 1.8.0
A buffer overflow vulnerability has been identified in The Linux Foundation Magma version 1.8.0 and prior. The issue arises in the 'decode_pdn_address' function within the PDNAddress.cpp file, where improper handling of crafted NAS packets can lead to a denial-of-service condition. This vulnerability is present in the 5G core implementation of Magma.
Exploitation of this vulnerability causes a denial-of-service condition by disrupting cellular communications at a city-wide level, as the vulnerability can be exploited by sending a single crafted NAS packet over the network.
To reproduce this vulnerability, send an 'Initial UE Message' S1AP packet containing a malformed PDN Address within the NAS payload to the Magma AMF. This can be done by establishing a connection as an unauthenticated user and transmitting the crafted packet over the network.
Users can upgrade to Magma version 1.9 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.