Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://cellularsecurity.org/ransacked |
|
Mon, 27 Jan 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation magma |
|
| CPEs | cpe:2.3:a:linuxfoundation:magma:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Magmacore
Magmacore magma |
Linuxfoundation
Linuxfoundation magma |
Thu, 23 Jan 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magmacore
Magmacore magma |
|
| CPEs | cpe:2.3:a:magmacore:magma:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Magmacore
Magmacore magma |
Thu, 23 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-617 | |
| Metrics |
cvssV3_1
|
Tue, 21 Jan 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a compromised base station or via an unauthenticated cellphone within range of a base station managed by the MME, causing a denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-23T19:10:01.775Z
Reserved: 2023-06-28T00:00:00.000Z
Link: CVE-2023-37029
Updated: 2025-01-23T19:08:39.185Z
Status : Analyzed
Published: 2025-01-21T23:15:10.117
Modified: 2025-01-27T14:39:48.927
Link: CVE-2023-37029
No data.
OpenCVE Enrichment
No data.