CVE-2025-25774
- EPSS 0.41%
- Veröffentlicht 12.03.2025 00:00:00
- Zuletzt bearbeitet 29.04.2025 15:04:59
An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Servic...
CVE-2025-1925
- EPSS 0.82%
- Veröffentlicht 04.03.2025 14:15:36
- Zuletzt bearbeitet 23.06.2025 15:10:37
A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to...
CVE-2025-1893
- EPSS 0.84%
- Veröffentlicht 04.03.2025 01:15:11
- Zuletzt bearbeitet 06.03.2025 12:21:35
A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of serv...
CVE-2024-56921
- EPSS 0.47%
- Veröffentlicht 03.02.2025 20:15:33
- Zuletzt bearbeitet 22.04.2025 14:58:46
An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response...
CVE-2024-57519
- EPSS 0.72%
- Veröffentlicht 28.01.2025 23:15:08
- Zuletzt bearbeitet 30.04.2025 16:42:42
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.
CVE-2024-24429
- EPSS 0.56%
- Veröffentlicht 22.01.2025 16:15:28
- Zuletzt bearbeitet 22.04.2025 17:27:25
A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.
CVE-2024-24430
- EPSS 0.78%
- Veröffentlicht 22.01.2025 15:15:12
- Zuletzt bearbeitet 22.04.2025 17:27:09
A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
CVE-2024-24432
- EPSS 0.27%
- Veröffentlicht 22.01.2025 15:15:12
- Zuletzt bearbeitet 22.04.2025 17:27:16
A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
CVE-2024-34235
- EPSS 0.78%
- Veröffentlicht 22.01.2025 15:15:12
- Zuletzt bearbeitet 22.04.2025 17:22:57
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resu...
CVE-2023-37015
- EPSS 0.78%
- Veröffentlicht 22.01.2025 15:15:11
- Zuletzt bearbeitet 22.04.2025 17:15:23
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Path Switch Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly cras...