Open5gs

Open5gs

191 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.2%
  • Veröffentlicht 07.08.2025 20:32:07
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_nsmf_pdusession_handle_release_sm_context of the file src/amf/nsmf-handler.c of the component AMF Service. The manipulation leads to...

  • EPSS 0.2%
  • Veröffentlicht 12.07.2025 18:32:07
  • Zuletzt bearbeitet 15.07.2025 13:14:24

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler of the component SCTP Partial Message Handler. The manipulation leads to reach...

  • EPSS 0.19%
  • Veröffentlicht 01.07.2025 11:32:07
  • Zuletzt bearbeitet 03.07.2025 15:14:12

A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertio...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 18.06.2025 00:00:00
  • Zuletzt bearbeitet 09.01.2026 19:16:06

A missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dev` field with a value with length greater th...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 18.06.2025 00:00:00
  • Zuletzt bearbeitet 09.07.2025 18:33:14

A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dnn` field with a value with length greater...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 18.06.2025 00:00:00
  • Zuletzt bearbeitet 09.07.2025 18:27:34

An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest packet with restoration indication = true and (teid = 0 or teid >= ogs_pfcp_pdr_teid_pool.size).

  • EPSS 0.78%
  • Veröffentlicht 10.06.2025 04:33:57
  • Zuletzt bearbeitet 12.06.2025 16:06:39

A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the component AMF/MME. The manipulation of the argument ran_ue...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 03.06.2025 18:00:22
  • Zuletzt bearbeitet 09.06.2025 15:13:24

A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possibl...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 03.06.2025 14:00:21
  • Zuletzt bearbeitet 13.06.2025 19:36:40

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_request_transfer of the file src/smf/ngap-handler.c of the component NGAP PathSwitchRequest Message Han...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 22.04.2025 00:00:00
  • Zuletzt bearbeitet 19.06.2025 00:23:24

An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value prop...