5.3

CVSS3.1

CVE-2023-37012 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` message missing a required `PLMN Identity` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:13 p.m.

6.3

CVSS3.1

CVE-2023-37009 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:14 p.m.

8.9

CVSS3.1

CVE-2023-36998 -

The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Number List value to the MME to overwrite the s…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: Feb. 6, 2025, 10:15 p.m.

8.6

CVSS3.1

CVE-2023-37023 -

Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:13 p.m.

8.6

CVSS3.1

CVE-2023-37021 -

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of serv…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

7.3

CVSS3.1

CVE-2023-37013 -

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state and crash, leading …

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

5.3

CVSS3.1

CVE-2023-37002 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Modification Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of servi…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:14 p.m.

5.7

CVSS3.1

CVE-2024-42012 -

GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging rights can therefore steal the user's Blocky password and from there impersonate th…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2025, 7:15 p.m.

8.6

CVSS3.1

CVE-2023-37018 -

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of servi…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

8.6

CVSS3.1

CVE-2023-37019 -

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.
Total resulsts: 342774
Page 6369 of 34,278
Β« previous page Β» next page
Filters