CVE ID | |
CVSS SCORE | 5.3, AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
AFFECTED VENDORS |
Microsoft |
AFFECTED PRODUCTS |
Azure |
VULNERABILITY DETAILS |
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the gNB-ID provided to the AP5GC endpoint. The product expects a unique id for each resource but does not enforce it correctly. An attacker can leverage this vulnerability to create a denial-of-service condition on connected clients. |
ADDITIONAL DETAILS |
04/25/24 – ZDI reported the vulnerability to the vendor. -- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product. |
DISCLOSURE TIMELINE |
|
CREDIT | Richard Y Lin, Salim S. I. (CTOne/TrendMicro) |