Open5gs

Open5gs

114 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.19%
  • Veröffentlicht 08.05.2024 17:15:07
  • Zuletzt bearbeitet 22.04.2025 17:47:24

An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration

  • EPSS 0.21%
  • Veröffentlicht 05.05.2024 00:15:07
  • Zuletzt bearbeitet 22.04.2025 17:53:03

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.

  • EPSS 0.08%
  • Veröffentlicht 05.05.2024 00:15:07
  • Zuletzt bearbeitet 22.04.2025 17:52:57

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 02.01.2024 22:15:09
  • Zuletzt bearbeitet 17.04.2025 19:15:57

An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 02.01.2024 22:15:09
  • Zuletzt bearbeitet 18.06.2025 16:15:22

An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

  • EPSS 0.07%
  • Veröffentlicht 03.10.2023 15:15:40
  • Zuletzt bearbeitet 21.11.2024 08:36:10

DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the s...

  • EPSS 0.07%
  • Veröffentlicht 03.10.2023 15:15:40
  • Zuletzt bearbeitet 21.11.2024 08:36:10

Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ...

  • EPSS 0.06%
  • Veröffentlicht 03.10.2023 15:15:40
  • Zuletzt bearbeitet 21.11.2024 08:36:11

An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.

  • EPSS 0.07%
  • Veröffentlicht 03.10.2023 15:15:40
  • Zuletzt bearbeitet 21.11.2024 08:36:11

Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure of sensitive information.

  • EPSS 0.51%
  • Veröffentlicht 01.02.2023 03:15:08
  • Zuletzt bearbeitet 27.03.2025 14:15:20

Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages, a protocol payload with any extension header length set to zer...