LiveActive security incident?Get immediate response
CVE Record

CVE-2024-14042: Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow

A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Diameter S6a Interface. Performing a manipulation of the argument os.len results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.7.2 is able to mitigate this issue. The patch is named e89aa79efe629ae90f59dcdf8847c117d9a7da86. It is suggested to upgrade the affected component.

MediumCVSS 6.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

A remotely reachable flaw in Open5GS can let malformed Diameter S6a data overflow memory in the HSS process. This could cause service disruption or affect data and system integrity. Public proof-of-concept material exists, but the supplied sources do not establish active exploitation.

Executive priority

Schedule prompt remediation for exposed telecom-core deployments, especially HSS systems reachable by multiple Diameter peers. The rating is moderate rather than critical because authentication is indicated and active exploitation is unconfirmed. Public proof-of-concept availability increases urgency. Resolve the conflicting 2.7.2 version data during change validation.

Technical view

Manipulating os.len in hss_ogs_diam_s6a_air_cb or hss_ogs_diam_s6a_ulr_cb within src/hss/hss-s6a-path.c can cause a stack-based buffer overflow. The supplied CVSS v2 assessment is 6.5 and indicates network access with authentication. Commit e89aa79efe629ae90f59dcdf8847c117d9a7da86 addresses the issue.

Likely exposure

Exposure is most likely where an affected Open5GS HSS accepts Diameter S6a traffic from reachable or insufficiently restricted peers. The narrative identifies versions through 2.7.1 as vulnerable. The structured affected list also includes 2.7.2, conflicting with the stated fixed release, so patch status should be verified directly.

Exploitation context

A public packet capture or proof-of-concept is referenced, making reproduction more accessible. Remote initiation is reported, although the CVSS vector indicates some authentication is required. The bundle marks KEV false and provides no evidence of active exploitation in production.

Researcher notes

The source bundle maps the flaw to CWE-119 and CWE-121 and reports partial confidentiality, integrity, and availability impact. It does not establish reliable code execution, observed attacks, or specific indicators. The version metadata is internally inconsistent: narrative and release references call 2.7.2 fixed, while the affected array includes it.

Mitigation direction

  • Upgrade Open5GS to version 2.7.2 or later, following vendor release guidance.
  • Confirm commit e89aa79efe629ae90f59dcdf8847c117d9a7da86 is present in custom or backported builds.
  • Restrict Diameter S6a access to authorized, trusted peers using existing network and peer controls.
  • Prioritize HSS availability protections and monitoring until remediation is confirmed.

Validation and detection

  • Inventory Open5GS HSS versions and identify deployments running 2.7.1 or earlier.
  • Verify the installed source or package contains the named corrective commit.
  • Review Diameter S6a reachability and confirm only authorized peers can connect.
  • Check HSS crash, restart, and memory-fault records for unexplained events.
  • Run approved defensive regression tests after upgrading; do not use production systems for proof-of-concept testing.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-119: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-121: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2024-14042 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.5 (2.0)
Known Exploited
No
Published

Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

4CVSS vectors
6Timeline events
1ADP providers
10Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: partial

CVSS vector scores

4 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.5CVSS 2.0MediumAV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C86.4VulDB
6.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C2.83.4VulDB
6.3CVSS 3.0MediumCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C2.83.4VulDB
5.3CVSS 4.0MediumCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:PVulDB

Vulnerability scoring details

Base CVSS 4.0 score

5.3Medium
CVSS 4.0 vector shape for CVE-2024-14042Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. Source timelineVulDB

    Advisory disclosed

  2. Source timelineVulDB

    VulDB entry created

  3. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  4. Source timelineVulDB

    VulDB entry last update

  5. CVE publishedCVE Program

    The CVE record was published.

  6. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aOpen5GS2.7.0, 2.7.1, 2.7.2Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-119 · source CWE mapping

Improper Restriction of Operations within the Bounds of a Memory Buffer

Improper Restriction of Operations within the Bounds of a Memory Buffer represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.

CWE-121 · source CWE mapping

Stack-based Buffer Overflow

Stack-based Buffer Overflow represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.