CVE-2024-24450 is a stack-based buffer overflow in OpenAirInterface CN5G AMF versions up to and including 2.0.0. The flaw is in the ngap_handle_pdu_session_resource_setup_response routine, where a memcpy operation can overflow a stack buffer when processing a PDU Session Resource Setup Response containing a sufficiently large FailedToSetupList information element (IE). An attacker with access to the N2 interface can trigger the vulnerable code path by sending a crafted NGAP message, causing memory corruption in the AMF process. The reported impact includes denial of service and potential code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2024-24450, targeting 5G core network AMF nodes that implement the NGAP protocol (TS 38.413/38.414). The main file, 'poc.py', is a Python script that uses the 'sctp' and 'pycrate' libraries to establish an SCTP connection from a simulated gNB (base station) to a target AMF. It sends a valid NG Setup Request, simulates a UE attach, and then delivers a malicious NGAP PDU Session Resource Setup Response containing 10,000 failed session entries. This is designed to overwhelm the AMF, potentially causing it to crash or become unresponsive, thus demonstrating a denial-of-service condition. The script is configurable for different IP addresses and ports, and is intended for red team or research use in controlled environments. The only other file is a minimal README. No hardcoded credentials or external network endpoints are present beyond the test IPs and standard NGAP port.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.