CVE-2024-24431: OPEN5GS

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.

Affected products

  • OPEN5GS OPEN5GS: version 2.7.0 only

Published 2024-11-15. Last modified 2026-06-17.