Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://cellularsecurity.org/ransacked |
|
Thu, 23 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-617 | |
| Metrics |
cvssV3_1
|
Tue, 21 Jan 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an `Emergency Number List` Information Element. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-23T19:07:21.253Z
Reserved: 2023-06-28T00:00:00.000Z
Link: CVE-2023-37024
Updated: 2025-01-23T19:07:13.401Z
Status : Undergoing Analysis
Published: 2025-01-21T23:15:09.500
Modified: 2025-01-23T19:15:09.950
Link: CVE-2023-37024
No data.
OpenCVE Enrichment
No data.