The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Number List value to the MME to overwrite the stack with arbitrary bytes. An attacker with a cellphone connection to any base station managed by the MME may exploit this vulnerability without having to authenticate with the LTE core.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://nextepc.com |
![]() ![]() |
https://cellularsecurity.org/ransacked |
![]() ![]() |
History
Thu, 06 Feb 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-121 | |
Metrics |
cvssV3_1
|
Wed, 22 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Number List value to the MME to overwrite the stack with arbitrary bytes. An attacker with a cellphone connection to any base station managed by the MME may exploit this vulnerability without having to authenticate with the LTE core. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-01-22T00:00:00.000Z
Updated: 2025-02-06T21:32:01.512Z
Reserved: 2023-06-28T00:00:00.000Z
Link: CVE-2023-36998

Updated: 2025-01-22T17:11:07.425Z

Status : Awaiting Analysis
Published: 2025-01-22T15:15:09.647
Modified: 2025-02-06T22:15:36.057
Link: CVE-2023-36998

No data.