In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
References
Configurations
History
21 Nov 2024, 06:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/open5gs/open5gs/commit/a0f2535cb5a29bba6dbbccdb90c74ccd770cc700 - Patch, Third Party Advisory | |
References | () https://www.trendmicro.com/en_us/research/23/i/attacks-on-5g-infrastructure-from-users-devices.html - |
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-1284 |
04 Jan 2022, 19:33
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
CPE | cpe:2.3:a:open5gs:open5gs:2.4.0:*:*:*:*:*:*:* | |
References | (MISC) https://github.com/open5gs/open5gs/commit/a0f2535cb5a29bba6dbbccdb90c74ccd770cc700 - Patch, Third Party Advisory | |
CWE | CWE-20 |
23 Dec 2021, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-12-23 04:15
Updated : 2024-11-21 06:32
NVD link : CVE-2021-45462
Mitre link : CVE-2021-45462
CVE.ORG link : CVE-2021-45462
JSON object : View
Products Affected
open5gs
- open5gs
CWE
CWE-1284
Improper Validation of Specified Quantity in Input