CVE-2023-37017 is a denial-of-service vulnerability affecting Open5GS MME versions up to 2.6.4. An unauthenticated attacker can remotely crash the MME by sending a malformed S1AP S1Setup Request message missing the Global eNB ID field, leading to repeated service disruption. This vulnerability has a high CVSS score of 8.6, indicating a critical impact on availability with low attack complexity. There is currently no public exploit code, evidence of active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.4CPE matchmatch criteria | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.