Vulnerabilities (CVE)

Filtered by vendor Linuxfoundation Subscribe
Filtered by product Magma
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37024 1 Linuxfoundation 1 Magma 2025-01-23 N/A 7.5 HIGH
A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an `Emergency Number List` Information Element.
CVE-2023-37026 1 Linuxfoundation 1 Magma 2025-01-23 N/A 6.5 MEDIUM
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Release Response` packet missing an expected `MME_UE_S1AP_ID` field.