6.5

CVE-2025-60633

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Free5gcFree5gc Version4.0.0
Free5gcFree5gc Version4.0.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.227
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-1287 Improper Validation of Specified Type of Input

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

https://github.com/free5gc/free5gc
Product
https://github.com/free5gc/free5gc/issues/702
Issue Tracking
https://github.com/free5gc/free5gc/issues/700
Issue Tracking
https://github.com/free5gc/free5gc/issues/701
Issue Tracking
https://github.com/free5gc/free5gc/issues/703
Issue Tracking