CVE-2024-56921

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 3, 2025
Updated: Feb 4, 2025
CWE ID 617

Summary

CVE-2024-56921 is a vulnerability affecting Open5gs version 2.7.2. A problem was found in the InitialUEMessage component of the system, where a Registration request received at a particular time can lead to a crash in the AMF. The root cause is the incorrect error handling of the gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response. Successful exploitation of this flaw could potentially result in denial-of-service conditions. It is recommended that users upgrade to a patched version of Open5gs to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share