CVE-2023-37024

A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an `Emergency Number List` Information Element.
References
Configurations

No configuration.

History

23 Jan 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-617
Summary
  • (es) Una afirmación alcanzable en la Entidad de administración móvil (MME) de las versiones de Magma &lt;= 1.8.0 (corregida en v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) permite a atacantes remotos bloquear la MME con un teléfono celular no autenticado enviando un paquete NAS que contiene un elemento de información de "Lista de números de emergencia".

21 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 23:15

Updated : 2025-01-23 19:15


NVD link : CVE-2023-37024

Mitre link : CVE-2023-37024

CVE.ORG link : CVE-2023-37024


JSON object : View

Products Affected

No product.

CWE
CWE-617

Reachable Assertion