Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqvv-r3g3-26rf

Опубликовано: 23 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

free5GC udm vulnerable to Invalid Curve Attack

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.

Пакеты

Наименование

github.com/free5gc/udm

go
Затронутые версииВерсия исправления

< 1.2.0

1.2.0

EPSS

Процентиль: 17%
0.00054
Низкий

7.5 High

CVSS3

Дефекты

CWE-327
CWE-347

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.

EPSS

Процентиль: 17%
0.00054
Низкий

7.5 High

CVSS3

Дефекты

CWE-327
CWE-347