CVE-2024-24447

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 120

Summary

CVE-2024-24447 is a newly identified cybersecurity vulnerability affecting oai-cn5g-amf versions up to 2.0.0. This issue involves a buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function, which can be exploited by attackers. By sending a specially crafted PDU Session Resource Setup Response with an empty Response Item list, they can trigger the buffer overflow, leading to a Denial of Service (DoS) condition. This vulnerability poses a significant risk and requires immediate attention from users to update their affected software to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share