omec-project amf
- <= 2.1.3-dev
A memory corruption vulnerability has been identified in the OMEC Project AMF component, specifically in versions up to 2.1.3-dev. The issue arises within an unknown function of the file 'ngap/dispatcher.go', related to the NGAP Message Handler. This vulnerability can be exploited remotely, and the exploit is publicly available.
Exploitation of this vulnerability leads to a crash of the AMF component, causing a denial of service.
The vulnerability can be reproduced by sending an NGAP packet that includes a non-printable string in the 'RANNodeName' information element of an 'NGSetupRequest'. This malformed input causes AMF to crash.
Users are advised to upgrade to version 2.2.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.