The post delves into two significant vulnerabilities in Microsoft Azure Private 5G Core (AP5GC), specifically CVE-2024-20685 and ZDI-CAN-23960, which can cause service outages and network disruptions. These issues stem from a systemic weakness in the lack of mandatory authentication between base stations and packet cores. The write-up details how these vulnerabilities can be exploited, the potential impacts, and mitigation strategies including IPSec, certificate-based authentication, and access control.
Sort: