📦 Magma

by Linuxfoundation

🔍 What is Magma?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-24421

CRITICAL CVSS 9.8 Jan 21, 2025

A type confusion vulnerability in Magma's NAS message decoding function allows attackers to execute arbitrary code or cause denial of service via specially crafted NAS packets. This affects Magma cell...

CVE-2024-24420

HIGH CVSS 7.5 Jan 21, 2025

A reachable assertion vulnerability in Magma's decode_linked_ti_ie function allows attackers to cause Denial of Service (DoS) by sending crafted NAS packets. This affects Magma versions up to 1.8.0, p...

CVE-2024-24423

HIGH CVSS 7.5 Jan 21, 2025

A buffer overflow vulnerability in Magma's decode_esm_message_container function allows attackers to cause Denial of Service via crafted NAS packets. This affects all systems running Magma <=1.8.0, pa...

CVE-2024-24416

HIGH CVSS 7.5 Jan 21, 2025

A buffer overflow vulnerability in Magma's decode_access_point_name_ie function allows attackers to cause denial of service via crafted NAS packets. This affects Magma cellular core network software u...

CVE-2024-24417

HIGH CVSS 7.5 Jan 21, 2025

A buffer overflow vulnerability in Magma's decode_protocol_configuration_options function allows attackers to cause Denial of Service (DoS) via crafted NAS packets. This affects Magma installations up...

CVE-2024-24418

HIGH CVSS 7.5 Jan 21, 2025

This vulnerability is a buffer overflow in the decode_pdn_address function of the Linux Foundation Magma software, affecting versions up to 1.8.0. It allows attackers to cause a Denial of Service (DoS...

CVE-2024-24419

HIGH CVSS 7.5 Jan 21, 2025

A buffer overflow vulnerability in Magma's decode_traffic_flow_template_packet_filter function allows attackers to cause denial of service via crafted NAS packets. This affects Magma cellular core net...

CVE-2023-37029

HIGH CVSS 7.5 Jan 21, 2025

CVE-2023-37029 allows attackers to cause denial of service by sending oversized NAS packets to Magma MME, crashing it via assertion failure. This affects Magma cellular core network deployments runnin...

CVE-2023-37032

HIGH CVSS 7.5 Jan 21, 2025

A stack-based buffer overflow vulnerability in Magma's Mobile Management Entity (MME) allows remote attackers to crash the service by sending specially crafted NAS packets with oversized Emergency Num...

CVE-2023-37024

HIGH CVSS 7.5 Jan 21, 2025

An unauthenticated remote attacker can crash the Mobile Management Entity (MME) in Magma cellular core networks by sending a specially crafted NAS packet containing an Emergency Number List Informatio...

CVE-2023-37037

MEDIUM CVSS 6.5 Jan 21, 2025

This vulnerability allows network-adjacent attackers to crash the Mobile Management Entity (MME) in Magma cellular core networks by sending a malformed S1AP S1Setup Request packet missing the Supporte...

CVE-2023-37030

MEDIUM CVSS 6.5 Jan 21, 2025

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sending a malformed S1AP Initial UE Message packet miss...

CVE-2023-37033

MEDIUM CVSS 6.5 Jan 21, 2025

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sending a malformed S1AP Initial UE Message packet miss...

CVE-2023-37025

MEDIUM CVSS 6.5 Jan 21, 2025

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sending a malformed S1AP Reset packet missing the Reset...

CVE-2023-37027

MEDIUM CVSS 6.5 Jan 21, 2025

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sending a malformed S1AP packet. This affects Magma ver...