Impact
The vulnerability originates from a state consistency error in the ngap_amf_handlers.c file of the NGSetup handler. This flaw allows an attacker to manipulate protocol messages and cause the system to enter an inconsistent internal state, potentially leading to misbehavior or denial of service. The weakness is categorized as CWE‑371, indicating improper state validation.
Affected Systems
The affected product is Linux Foundation Magma, specifically version 1.9.0. The issue is located in the NGSetup component; no additional affected versions have been identified.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity, and the vulnerability is exploitable remotely, as publicly available exploits have been released. Because EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, the exploit demand is unclear, but the remote nature increases the risk. An attacker could manipulate NGAP messages to disrupt service or corrupt state.
OpenCVE Enrichment