Magma
Vendor:
First CVE: Jan 21, 2025 · Active for 1 year
22
Total CVEs
More Total CVEs than 94% of tracked products
22.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Magma over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2025
18 months ago
Most Recent CVE
Jan 21, 2025
549 days ago
CVE Severity & Scoring
Magma22 CVEs
50%
45%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network11 (50.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None22 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24421CRITICAL A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or | Jan 21, 2025 | 9.8 | 27 | NO | NO |
CVE-2023-37032HIGH A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attacke | Jan 21, 2025 | 7.5 | 23 | NO | NO |
CVE-2024-24423HIGH The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_esm_message_container | Jan 21, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-24422HIGH The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack overflow in the decode_protocol_configuration_ | Jan 21, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-24420HIGH A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Se | Jan 21, 2025 | 7.5 | 21 | NO | NO |
CVE-2023-37034MEDIUM A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adja | Jan 21, 2025 | 6.5 | 21 | NO | NO |
CVE-2023-37033MEDIUM A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adja | Jan 21, 2025 | 6.5 | 21 | NO | NO |
CVE-2024-24419HIGH The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_ | Jan 21, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-24418HIGH The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_pdn_address function a | Jan 21, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-24417HIGH The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration | Jan 21, 2025 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Magma
Top CWEs
Versions
No cataloged versions.