Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-24451. PoCs published by SpiralBL0CK.
AI-analyzed exploit summary The repository contains a functional exploit for CVE-2024-24451, targeting a 3GPP-Aligned AMF (Access and Mobility Management Function) via crafted NGAP messages. The exploit uses SCTP connections to exhaust AMF resources through malicious NGAP payloads, including gNB-ID and slice contention attacks.
Description
A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.
Exploits (1)
The repository contains a functional exploit for CVE-2024-24451, targeting a 3GPP-Aligned AMF (Access and Mobility Management Function) via crafted NGAP messages. The exploit uses SCTP connections to exhaust AMF resources through malicious NGAP payloads, including gNB-ID and slice contention attacks.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H