CVE-2024-20685: Azure Private 5G Core Denial of Service Vulnerability

Overview

Severity
Medium (CVSS 5.9)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-Apr
Released
2024-04-09
EPSS Score
0.78% (percentile: 73.7%)

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires multiple conditions to be met, such as specific application behavior, user actions, manipulation of parameters passed to a function, and impersonation of an integrity level token.

Affected Products (1)

Azure

  • Azure Private 5G Core

Security Updates (1)

Acknowledgments

Salim S.I, Richard Y Lin, Atlas Huang (CTOne/TrendMicro) with <a href="https://www.zerodayinitiative.com/">Trend Micro Zero Day Initiative</a>

Revision History

  • 2024-04-09: Information published.