Cyber Resilience

CVE-2023-37018

HighPublic PoC

Published: 22 January 2025

Published
22 January 2025
Modified
22 April 2025
KEV Added
Patch
CVSS Score v3.1 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score 0.0031 54.1th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2023-37018 is a high-severity Reachable Assertion (CWE-617) vulnerability in Open5Gs Open5Gs. Its CVSS base score is 8.6 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Application or System Exploitation (T1499.004); ranked in the top 45.9% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified are NIST 800-53 SC-5 (Denial-of-service Protection) and SI-10 (Information Input Validation).

Deeper analysis

CVE-2023-37018 is a vulnerability in Open5GS Mobility Management Entity (MME) versions up to and including 2.6.4. It involves a reachable assertion (CWE-617) that can be remotely triggered by a malformed ASN.1 packet over the S1AP interface. An attacker sends a UE Capability Info Indication message missing the required MME_UE_S1AP_ID field, causing the assertion to fail.

The vulnerability has a CVSS v3.1 base score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), indicating high severity due to network accessibility, low attack complexity, no privileges or user interaction required, changed scope, and high availability impact. Any unauthenticated remote attacker with access to the S1AP interface can exploit it by transmitting the malformed message, crashing the MME process. Repeated exploitation results in sustained denial of service against the MME.

Mitigation details are available in the advisory published at https://cellularsecurity.org/ransacked.

EU & UK References

Vulnerability details

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash…

more

the MME, resulting in denial of service.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

Malformed packet triggers remote assertion failure, enabling direct exploitation of the service for denial of service via application crash.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

CVEs Like This One

CVE-2026-2523Same product: Open5Gs Open5Gs
CVE-2024-24430Same product: Open5Gs Open5Gs
CVE-2024-34235Same product: Open5Gs Open5Gs
CVE-2023-37021Same product: Open5Gs Open5Gs
CVE-2023-37015Same product: Open5Gs Open5Gs
CVE-2023-37016Same product: Open5Gs Open5Gs
CVE-2023-37017Same product: Open5Gs Open5Gs
CVE-2023-37023Same product: Open5Gs Open5Gs
CVE-2024-24427Same product: Open5Gs Open5Gs
CVE-2024-24428Same product: Open5Gs Open5Gs

Affected Assets

open5gs
open5gs
≤ 2.6.4

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Validates incoming S1AP packets, such as UE Capability Info Indication, to ensure required fields like MME_UE_S1AP_ID are present, preventing the assertion failure from malformed ASN.1 input.

prevent

Ensures secure error handling during ASN.1 parsing over the S1AP interface to avoid crashing the MME process when encountering malformed packets.

prevent

Implements denial-of-service protections on the S1AP interface, such as rate limiting and resource controls, to mitigate repeated malformed packet transmissions causing MME crashes.

References