A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsm_build_pdu_session_establishment_accept of the file /src/smf/gsm-build.c of the component SMF. The manipulation resul…
Medium CVSS 4.3
Summary
A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsm_build_pdu_session_establishment_accept of the file /src/smf/gsm-build.c of the component SMF. The manipulation results in denial of service. The attack can be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/open5gs/open5gs/ Product
- https://github.com/open5gs/open5gs/issues/4447 Exploit
- https://vuldb.com/submit/808483 Third Party Advisory
- https://vuldb.com/vuln/362563 Third Party Advisory
- https://vuldb.com/vuln/362563/cti Permissions Required
Timeline
- nvd_ingest NVD