CVE-2024-24459
https://notcve.org/view.php?id=CVE-2024-24459
An invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload. • http://athonet.com https://cellularsecurity.org/ransacked • CWE-125: Out-of-bounds Read •
CVE-2024-45969
https://notcve.org/view.php?id=CVE-2024-45969
NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message. • https://encs.eu/news/critical-security-vulnerabilities-discovered-in-mz-automations-mms-client https://github.com/mz-automation/libiec61850/commit/7afa40390b26ad1f4cf93deaa0052fe7e357ef33 • CWE-476: NULL Pointer Dereference •
CVE-2024-24449
https://notcve.org/view.php?id=CVE-2024-24449
An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF. • https://cellularsecurity.org/ransacked https://openairinterface.org • CWE-824: Access of Uninitialized Pointer •
CVE-2024-24425
https://notcve.org/view.php?id=CVE-2024-24425
Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. • https://cellularsecurity.org/ransacked https://github.com/OPENAIRINTERFACE/openair-epc-fed https://github.com/magma/magma • CWE-125: Out-of-bounds Read •
CVE-2024-24446
https://notcve.org/view.php?id=CVE-2024-24446
An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF. • https://cellularsecurity.org/ransacked https://openairinterface.org • CWE-476: NULL Pointer Dereference •