Sceawere

Vulnerability Detail

CVE-2026-101035UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

UERANSIM Uncaught Exception Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
aligungr
Product
UERANSIM
Attack Type
Uncaught Exception
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipulation can lead to uncaught exception. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac. It is best practice to apply a patch to resolve this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-28T10:16:42.453Z",
  "pubdate": "2026-09-28T10:16:42.453Z",
  "executiveSummary": "A critical vulnerability exists in UERANSIM versions up to 3.3.0 within the nr-gnb component. The flaw is rooted in improper error handling during the processing of NAS messages, specifically within the DecodePlainMmMessage function.\nThis vulnerability is classified as an uncaught exception, which can be triggered remotely by an unauthenticated attacker to cause a denial-of-service condition, effectively crashing the nr-gnb service.\nThe flaw stems from insufficient input validation, allowing specially crafted packets to disrupt the application's runtime state.\nGiven that public exploit code exists, the risk is elevated, and immediate patching is required to prevent remote exploitation and service degradation.",
  "technicalDetails": "The vulnerability resides in the src/lib/nas/encode.cpp file within the nr-gnb component of UERANSIM. The specific function identified as vulnerable is DecodePlainMmMessage, which is responsible for parsing NAS (Non-Access Stratum) plain Mobility Management (MM) messages.\nThe root cause of this vulnerability is an unhandled exception generated during the message decoding process. When the function receives a malformed or unexpected data structure within a NAS message, the application fails to perform adequate bounds checking or type validation. This failure leads to an exception being thrown that is not captured by a corresponding catch block, resulting in the termination of the nr-gnb process.\nThe attack vector is remote, meaning an adversary can transmit a malicious payload over the network targeting the UERANSIM service without requiring prior authentication or administrative privileges. The exploitation flow begins with the attacker crafting a NAS message containing intentionally malformed parameters that violate the expected protocol schema defined by the 3GPP standards implemented in UERANSIM.\nWhen this malicious packet reaches the nr-gnb component, it is passed to the DecodePlainMmMessage function. Because the function lacks robust input sanitization and error handling, the processing logic encounters an illegal state or invalid memory access scenario while interpreting the payload. This triggers an runtime exception. Since the application fails to gracefully handle this exception, the entire nr-gnb service terminates abruptly.\nThe impact of a successful exploit is a Denial of Service (DoS) of the affected UERANSIM instance. Because the service is critical to the simulated 5G gNodeB operations, this crash prevents the network node from servicing legitimate UEs (User Equipment), effectively disrupting communication within the simulated environment.\nThe vulnerability affects all versions of UERANSIM up to and including 3.3.0. As exploit material is currently available in the public domain, the threat of active exploitation is significant, requiring immediate deployment of the patch referenced by commit 1ae9bf2062b57595dbcbc4bc1d0a0ccf06815bac to introduce proper exception handling mechanisms."
}
CVE-2026-101035: UERANSIM Uncaught Exception Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere