CVE-2024-24442 Details
Description
A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP message.
A NULL pointer dereference vulnerability has been identified in the OpenAirInterface CN5G Access and Mobility Management Function (AMF) versions through 2.0.0. The issue arises in the ngap_app::handle_receive function, where the application fails to properly handle unsupported NGAP protocol messages. This flaw allows attackers to send crafted NGAP messages that cause a denial-of-service condition by crashing the AMF.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 21, 2025CISA-ADP
Assessed Jan 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cellularsecurity.org/ransacked | CISA-ADP | BundleTechnical Analysis |
| https://cellularsecurity.org/ransacked | [email protected] | BundleTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| OpenAirInterface CN5G AMF | All versions |
CPE
Remediation
| |
| Open5GS | <= 2.6.4 (semver) |
CPE
Remediation
| |
| Magma | All versions |
CPE
Remediation
| |
| Athonet vEPC MME | All versions |
CPE
Remediation
| |
| NextEPC | All versions |
CPE
Remediation
| |
| SD-Core | All versions |
CPE
Remediation
| |
| srsRAN | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 24, 2025 | CVE Modified | CISA-ADP |
| Jan 21, 2025 | New CVE Received | [email protected] |
Volerion