Impact
A memory corruption flaw occurs in the ULInformationTransfer function within UERANSIM's nr-gnb component. Manipulating the dedicatedNASMessage argument can overwrite arbitrary memory locations, which may allow an attacker to execute arbitrary code, crash the service or otherwise disrupt the network function. The vulnerability is directly exploitable and has been publicly demonstrated, indicating a clear risk to confidentiality, integrity and availability of the affected system.
Affected Systems
Versions of aligungr UERANSIM up to 3.3.0 are affected, specifically the handler.cpp file handling ULInformationTransfer in the nr-gnb component. The flaw is listed in multiple public advisories and vulnerability databases, and it has been reported to the vendor without response.
Risk and Exploitability
The attack can be launched remotely, and an exploit is available online, meaning an adversary does not need privileged access. The CVSS score of 6.9 shows moderate to high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is memory corruption (CWE‑119), it can allow arbitrary code execution if the attacker can influence the memory state during the vulnerable function. The lack of a published patch and the presence of a public exploit increase the risk profile for exposed UERANSIM installations.
OpenCVE Enrichment