Lucene search

K
osvGoogleOSV:GHSA-CQVV-R3G3-26RF
HistoryOct 23, 2023 - 3:30 a.m.

free5GC udm vulnerable to Invalid Curve Attack

2023-10-2303:30:30
Google
osv.dev
8
free5gc
udm
invalid curve attack
vulnerability
pkg/suci/suci.go
software
go before 1.19
shared secret
uncompressed public key
private key

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

28.1%

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker’s public key.

CPENameOperatorVersion
github.com/free5gc/udmlt1.2.0

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

28.1%

Related for OSV:GHSA-CQVV-R3G3-26RF