Impact
In the osmo-bsc Base Station Controller, the function ipaccess_proxy_read_msg() processes IPA frame lengths without proper bounds checking. When an attacker supplies a crafted IPA frame, the routine writes beyond the allocated heap buffer, which can corrupt adjacent memory and potentially allow execution of arbitrary code. This is a classic heap buffer overflow (CWE‑122) that can compromise confidentiality, integrity, and availability if successfully exploited.
Affected Systems
All Osmocom osmo-bsc releases from version 1.0.1 up to and including 1.14.1 are vulnerable. The issue was introduced in the 1.0.1 release and persists through the 1.14.1 release. The specific version tracking provided by the CNA confirms the affected range. No other Osmocom osmo-bsc releases are known to be affected.
Risk and Exploitability
The EPSS score of 0.00141 (less than 1%) indicates a very low exploitation probability, despite the CVSS score of 7.5 which signals high severity when an attacker can control IPA frame length. The primary attack vector is remote: an entity with the ability to send IPA frames to the base station controller may trigger the overflow. The absence of authentication in the provided description suggests that an attacker could use a compromised handset or rogue device connected to the network, making the risk significant for operational deployments.
OpenCVE Enrichment