Vulnerability index

Browse CVEs

146 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open5gs HIGH 8.6
CVE-2024-24429

A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted N…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2024-34235

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 7.5
CVE-2024-24430

A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS p…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs MEDIUM 5.3
CVE-2024-24432

A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS pack…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37015

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37016

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37017

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37018

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37019

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37020

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37021

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37023

Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 7.5
CVE-2023-37022

Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_U…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 7.5
CVE-2023-37014

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 7.3
CVE-2023-37013

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs MEDIUM 6.3
CVE-2023-37009

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 6.3
CVE-2023-37010

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 6.3
CVE-2023-37011

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37005

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37006

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37007

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37008

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type c…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37012

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37002

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37003

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37004

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs HIGH 7.5
CVE-2024-24427

A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packe…

Fix: after 2.6.4
Fix from $1,950 2025-01-21
Open5gs HIGH 7.5
CVE-2024-24428

A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP …

Fix: after 2.6.4
Fix from $1,950 2025-01-21
Open5gs HIGH 7.5
CVE-2024-24431

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS pack…

No fix yet
Fix from $1,950 2024-11-15
Open5gs HIGH 7.5
CVE-2024-51179

An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User P…

No fix yet
Fix from $1,950 2024-11-12