CVE-2023-37024

A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an `Emergency Number List` Information Element.
References
Configurations

No configuration.

History

23 Jan 2025, 19:15

Type Values Removed Values Added
CWE CWE-617
Summary
  • (es) Una afirmación alcanzable en la Entidad de administración móvil (MME) de las versiones de Magma &lt;= 1.8.0 (corregida en v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) permite a atacantes remotos bloquear la MME con un teléfono celular no autenticado enviando un paquete NAS que contiene un elemento de información de "Lista de números de emergencia".
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

21 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 23:15

Updated : 2025-01-23 19:15


NVD link : CVE-2023-37024

Mitre link : CVE-2023-37024

CVE.ORG link : CVE-2023-37024


JSON object : View

Products Affected

No product.

CWE
CWE-617

Reachable Assertion