Description
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cqvv-r3g3-26rf | free5GC udm vulnerable to Invalid Curve Attack |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T20:45:40.833Z
Reserved: 2023-10-23T00:00:00.000Z
Link: CVE-2023-46324
No data.
Status : Modified
Published: 2023-10-23T01:15:07.637
Modified: 2024-11-21T08:28:18.317
Link: CVE-2023-46324
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA