What is CVE-2024-14043?
A vulnerability was determined in Open5GS up to version 2.7.1, affecting the function mme_s6a_subscription_data_from_avp in the Diameter S6a interface. Manipulation of the msisdn_len argument leads to a heap-based buffer overflow. It is critical to update to the latest patched version.
Azərbaycanca: Open5GS-in 2.7.1-ə qədər versiyalarında Diameter S6a interfeysində heap-based buffer overflow zəifliyi aşkarlanıb. Bu, msisdn_len arqumentinin manipulyasiyası nəticəsində yaranır. Təcili olaraq proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Open5GS
FAQ2
Which interface of Open5GS does the CVE-2024-14043 vulnerability affect?
The vulnerability affects the Diameter S6a interface of Open5GS.
What is the recommended mitigation for CVE-2024-14043?
It is recommended to update Open5GS to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.