CVE-2023-37035
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 476
Summary
CVE-2023-37035 is a null pointer dereference vulnerability affecting the Mobile Management Entity (MME) in Magma versions prior to 1.9. This issue arises when the MME receives an S1AP `S1Setup Request` packet lacking the expected `Global eNB ID` field. Exploitation of this vulnerability enables network-adjacent attackers to crash the MME, potentially disrupting network services. The vulnerability has been addressed in Magma version 1.9 with commit 08472ba98b8321f802e95f5622fa90fec2dea486.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.