CVE-2024-24450
MEDIUMOpenAirInterface CN5G AMF <= 2.0.0 - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-24450. PoCs published by SpiralBL0CK.
AI-analyzed exploit summary This repository contains a functional PoC exploit for CVE-2024-24450, targeting a 3GPP-compliant AMF (Access and Mobility Management Function) via crafted NGAP messages. The exploit sends a large number of failed PDU session setup responses to trigger instability or crash in the AMF.
Description
Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response with a suffciently large FailedToSetupList IE.
Exploits (1)
This repository contains a functional PoC exploit for CVE-2024-24450, targeting a 3GPP-compliant AMF (Access and Mobility Management Function) via crafted NGAP messages. The exploit sends a large number of failed PDU session setup responses to trigger instability or crash in the AMF.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H