[CVE-2024-14043] A vulnerability was determined in Open5GS up to 2.7.1. This

CVE-2024-14043 | CVSS: 6.3 | 严重级别: MEDIUM

A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data_from_avp of the file src/mme/mme-fd-path.c of the component Diameter S6a Interface. Executing a manipulation of the argument msisdn_len can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.7.2 is able to resolve this issue. This patch is called 7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304. Upgrading the affected component is recommended.

参考链接:
https://github.com/open5gs/open5gs/
https://github.com/open5gs/open5gs/commit/7ea82cb87bb65c3694d8d7c7a5efed1c4d3c93
https://github.com/open5gs/open5gs/files/15051238/capture.pcap.gz

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
本网站所有资源、文章、工具介绍、漏洞情报仅用于网络安全合规学习、科研、授权测试用途。严禁用于未授权检测、入侵、破坏等违法行为,违者自行承担全部法律责任。本站所有工具均为开源公开项目,不提供非法攻击程序与违规资源下载。
© 2026 安域星联技术社区 · 专注网络安全学习与开源资源分享 | 蒙ICP备2026002266号
滚动至顶部