CVE-2024-51179
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-51179 is a recently disclosed vulnerability affecting Open 5GS version 2.7.1. This issue enables a remote attacker to trigger a denial of service (DoS) condition on Network Function Virtualizations (NFVs), specifically the User Plane Function (UPF) and Session Management Function (SMF). The vulnerability lies in the Packet Data Unit (PDU) session establishment process, allowing an adversary to send malicious packets that can cause the affected systems to become unresponsive or crash. This can lead to network disruptions and potential service outages for users, making it a significant concern for organizations utilizing Open 5GS in their 5G networks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- 5Gs