Athonet MME Buffer Overflow Vulnerability Leading to Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in the Athonet MME component of HPE Athonet Core products. This vulnerability is triggered by an E-RAB Release Command packet that contains a malformed NAS PDU, causing the MME to crash. The issue is present in Athonet Core versions 11.1 and below, as well as in versions 11.2 through 11.6 under certain configuration settings.

Impact

Exploitation of this vulnerability causes the Athonet MME to crash, leading to a denial-of-service condition on the cellular network.

Remediation

Users are advised to upgrade to HPE Athonet Core 11.6. For versions 11.2 and later but earlier than 11.6, the upgrade to 11.6 is recommended. After upgrading, migrate the configuration to the 'eMME' (Enhanced MME) configuration page. HPE Support can assist with the migration if needed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.