CyRC Vulnerability Advisory: CVE-2023-23846 Denial-of-Service Vulnerability in Open5GS GTP Library

By : Nata Kesuma | Sunday, February 05 2023 - 22:55 IWST

The Synopsys Cybersecurity Research Center (CyRC)
The Synopsys Cybersecurity Research Center (CyRC)

INDUSTRY.co.id - Singapore- The Synopsys Cybersecurity Research Center (CyRC) has exposed CVE-2023-23846, a vulnerability in Open5GS. Open5GS is a C-language open source implementation that provides both 4G/LTE enhanced packet core (EPC) and 5G functionalities for mobile network deployments with an AGPLv2 or commercial license.

It is primarily used to build and deploy private LTE/5G telecom network core functions by researchers and commercial entities such as telecom network operators.

Due to insufficient length validation in the Open5GS GTP library when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages, a protocol payload with any extension header length set to zero causes an infinite loop. The affected process becomes immediately unresponsive, resulting in denial of service and excessive resource consumption.

Because the code resides in a common GTP library that is shared across different functions, this vulnerability is effectively present in all deployed endpoints configured to accept and handle GTP-U messages, including the 5G user plane function (UPF, provided by open5gs-upfd), the 5G session management function (SMF, provided by open5gs-smfd), and the LTE/EPC serving gateway user plane function (SGW-U, provided by open5gs-sgwud).

News Comment

Today's Industry

Left to Right, the President Director of WIFI, Yune Marketatmo, and the President Director of DOOH, Vicktor Aritonang, pose for a group photo after signing of the agreement. (Public Relation of WIFI and DOOH)

Senin, 03 Maret 2025 - 14:03 WIB

Solusi Sinergi Collaborates with Era Media to Reach 40 Million Internet Customers with Artificial Intelligence

PT Solusi Sinergi Digital Tbk (WIFI) announced a strategic collaboration with PT Era Media Sejahtera Tbk (DOOH) to support the WIFI project in marketing affordable internet for the people, which…

The President Director of PART, Hamim, talks with the former Agriculture Minister, Anton Apriyantono, and the capital market observer, Yohannis Hans Kwee, at the Nusantara Investment & Opportunities 2025, in Jakarta, Tuesday (11/02/2025)

Selasa, 11 Februari 2025 - 16:31 WIB

Cipta Perdana Lancar Ready to Expand and Diversify for Sustainable Growth

Since its establishment in 2007, PT Cipta Perdana Lancar Tbk (PART) has continued to transform into a major partner in the supply of spare parts for the automotive, sanitary, and electronics…

The Jakarta Convention Center (1001malam.com)

Rabu, 22 Januari 2025 - 12:53 WIB

MICE Activities at JCC Halted, PT GSP Continues Legal Process

PT Graha Sidang Pratama (PT GSP), the investor and manager of the Jakarta Convention Center (JCC), revealed that the company is currently unable to run Meeting, Incentive, Convention and Exhibition…

Images By : Freepik

Sabtu, 14 September 2024 - 16:56 WIB

Essential Tips for Choosing Personal Health Insurance in the US

Choosing the right health insurance plan in the United States can be a complex task, especially with the variety of options available and the ever-changing landscape of healthcare policy. Here…

Images By : Freepik

Sabtu, 14 September 2024 - 16:53 WIB

The Top 10 Insurance Companies in the US for 2024

In the ever-evolving landscape of insurance, selecting the right company can significantly impact your financial security and peace of mind.