3.1
CVE-2026-10565
- EPSS 0.22%
- Veröffentlicht 02.06.2026 01:30:09
- Zuletzt bearbeitet 02.06.2026 13:03:31
- Quelle cna@vuldb.com
- CVE-Watchlists
- Unerledigt
Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition
A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellern/a
≫
Produkt
Open5GS
Version
2.7.0
Status
affected
Version
2.7.1
Status
affected
Version
2.7.2
Status
affected
Version
2.7.3
Status
affected
Version
2.7.4
Status
affected
Version
2.7.5
Status
affected
Version
2.7.6
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.128 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
|
| cna@vuldb.com | 1.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 2.1 | 3.9 | 2.9 |
AV:N/AC:H/Au:S/C:N/I:N/A:P
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
https://github.com/open5gs/open5gs/
https://vuldb.com/vuln/367672
https://vuldb.com/vuln/367672/cti
https://vuldb.com/cve/CVE-2026-10565
https://vuldb.com/submit/818938
https://github.com/open5gs/open5gs/issues/4497
https://github.com/open5gs/open5gs/pull/4501
https://github.com/user-attachments/files/27111025/N2-SMC-Concurrent.zip