CVE-2023-37033 is a Null Pointer Dereference vulnerability in the Mobile Management Entity (MME) component of Magma versions 1.8.0 and earlier. An unauthenticated, network-adjacent attacker can trigger a denial-of-service by sending a malformed S1AP Initial UE Message packet lacking an EUTRAN_CGI field, causing the MME to crash. This vulnerability has a CVSS score of 6.5 (Medium) due to its low attack complexity and high availability impact, with no confidentiality or integrity impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:magma:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.