Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
History

Tue, 19 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Magma
Magma magma
Oai Epc Federation
Oai Epc Federation oai Epc Federation
Weaknesses CWE-125
CPEs cpe:2.3:a:magma:magma:*:*:*:*:*:*:*:*
cpe:2.3:a:oai_epc_federation:oai_epc_federation:*:*:*:*:*:*:*:*
Vendors & Products Magma
Magma magma
Oai Epc Federation
Oai Epc Federation oai Epc Federation
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 18:45:00 +0000

Type Values Removed Values Added
Description Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-15T00:00:00

Updated: 2024-11-19T16:34:30.607Z

Reserved: 2024-01-25T00:00:00

Link: CVE-2024-24425

cve-icon Vulnrichment

Updated: 2024-11-19T16:34:22.348Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-15T19:15:05.927

Modified: 2024-11-19T17:35:09.450

Link: CVE-2024-24425

cve-icon Redhat

No data.