Open5gs

Open5gs

191 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.17%
  • Veröffentlicht 01.01.2026 23:15:56
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was identified in Open5GS up to 2.7.6. Affected is the function sgwc_s11_handle_create_session_request of the file src/sgwc/s11-handler.c of the component GTPv2-C F-TEID Handler. Such manipulation leads to denial of service. The attac...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 29.12.2025 06:32:06
  • Zuletzt bearbeitet 24.02.2026 07:17:00

A flaw has been found in Open5GS up to 2.7.5. This affects the function decode_ipv6_header/ogs_pfcp_pdr_rule_find_by_packet of the file lib/pfcp/rule-match.c of the component PFCP Session Establishment Request Handler. Executing a manipulation can le...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 19.12.2025 16:32:08
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component PFCP. The manipulation results in improper initialization. It is possible t...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 19.12.2025 16:02:11
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_or_add/ogs_pfcp_qer_find_or_add in the library lib/pfcp/context.c of the component QER/FAR/URR/PDR. Th...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 19.12.2025 16:02:07
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component FAR-ID Handler. Executing a manipulation can lead to null pointer dereference. The attack may be per...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 06.01.2026 20:01:32

An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has...

  • EPSS 0.32%
  • Veröffentlicht 10.11.2025 19:15:57
  • Zuletzt bearbeitet 11.12.2025 23:30:00

In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.

  • EPSS 0.33%
  • Veröffentlicht 27.10.2025 12:47:57
  • Zuletzt bearbeitet 29.10.2025 11:15:44

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is achieved by sending the creation of an NF with an invalid type via SBI and then requesting its data. ...

  • EPSS 0.4%
  • Veröffentlicht 27.10.2025 12:47:32
  • Zuletzt bearbeitet 29.10.2025 11:15:44

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and r...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 17.09.2025 00:00:00
  • Zuletzt bearbeitet 23.09.2025 15:45:10

Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference when a multipart/related HTTP POST request with an empty HTTP body is sent to the SBI of either AMF, AUSF, BSF, NRF, NSSF, PCF, SMF,...