omec-project amf
- <= 2.1.3-dev
A null pointer dereference vulnerability has been identified in the OMEC Project AMF component, affecting versions through 2.1.3-dev. The issue arises in the NGAP message handling, specifically within the UERadioCapabilityCheckResponse function, located in the ngap/dispatcher.go file. This vulnerability can be exploited remotely, leading to a crash of the AMF process.
Exploitation of this vulnerability causes a segmentation fault, crashing the AMF process.
The vulnerability can be reproduced by sending a malformed UERadioCapabilityCheckResponse NGAP message. This message should be crafted to include per data that is out of range, which will trigger the null pointer dereference when the AMF attempts to process the message.
Users are advised to upgrade to OMEC Project AMF version 2.2.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.