Vulnerability Description
In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.
CVSS Score
5.5
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Free5Gc | Free5Gc | 3.2.1 |
References
- https://github.com/free5gc/free5gc/issues/402ExploitIssue TrackingThird Party Advisory
- https://www.trendmicro.com/en_us/research/23/j/asn1-vulnerabilities-in-5g-cores.
- https://github.com/free5gc/free5gc/issues/402ExploitIssue TrackingThird Party Advisory
- https://www.trendmicro.com/en_us/research/23/j/asn1-vulnerabilities-in-5g-cores.
FAQ
What is CVE-2022-43677?
CVE-2022-43677 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.
How severe is CVE-2022-43677?
CVE-2022-43677 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-43677?
Check the references section above for vendor advisories and patch information. Affected products include: Free5Gc Free5Gc.