8.2

CVE-2026-108105

Open5GS through 2.8.0 MME Reachable Assertion via GTPv1 SGSN Context Request

Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs. Attackers sending GTPv1-C traffic from a configured SGSN address with a known UE IMSI or P-TMSI can supply an invalid address length to terminate open5gs-mmed, denying service to all subscribers.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleropen5gs
≫
Produkt open5gs
Default Statusunaffected
Version <= 2.8.0
Version 0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 8.2 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
disclosure@vulncheck.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

https://github.com/open5gs/open5gs
https://github.com/open5gs/open5gs/commit/346ce7a5e5cf2812bac3af042b5afba35bcf4f89
https://github.com/open5gs/open5gs/security/advisories/GHSA-9crh-64c8-56q6
https://github.com/open5gs/open5gs/blob/v2.8.0/src/mme/mme-gn-handler.c#L208-L217
https://www.vulncheck.com/advisories/open5gs-through-2.8.0-mme-reachable-assertion-via-gtpv1-sgsn-context-request