Impact
This vulnerability resides in the Registration Complete Message Handler within the AMF component of Linux Foundation Magma. An attacker can manipulate the message handling process, causing the system to accept authentication credentials that are not properly verified. The result is that an unauthenticated user gains the privileges granted to a legitimately authenticated session. The flaw is classified under CWE‑287 and would allow an attacker to impersonate legitimate entities or obtain unauthorized access to services managed by the AMF.
Affected Systems
The affected product is Linux Foundation Magma version 1.9.0. The flaw is located in the tasks/amf/amf_fsm.cpp component. Systems running this exact version without additional authentication safeguards are at risk. No other affected versions are mentioned, so any installations matching this configuration should be evaluated for exposure.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. While the EPSS score is not available, a publicly disclosed exploit that can be launched remotely indicates a tangible exploitation risk. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote because the description explicitly states that the attack can be launched remotely, and the exploit is public.
OpenCVE Enrichment