CVE-2024-14044
- EPSS 0.48%
- Veröffentlicht 12.08.2026 01:17:06
- Zuletzt bearbeitet 12.08.2026 20:59:21
A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Diameter Rx Handler. The manipulation of the argument num_of_media_component/num_of_sub leads t...
CVE-2024-14043
- EPSS 0.48%
- Veröffentlicht 11.08.2026 23:15:14
- Zuletzt bearbeitet 12.08.2026 20:59:21
A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data_from_avp of the file src/mme/mme-fd-path.c of the component Diameter S6a Interface. Executing a manipulation of the argument msis...
CVE-2024-14042
- EPSS 0.48%
- Veröffentlicht 11.08.2026 19:15:09
- Zuletzt bearbeitet 12.08.2026 20:59:21
A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Diameter S6a Interface. Performing a manipulation of the argument os.len r...
CVE-2026-15720
- EPSS 0.37%
- Veröffentlicht 14.07.2026 19:16:51
- Zuletzt bearbeitet 15.07.2026 20:58:48
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
CVE-2026-15194
- EPSS 0.12%
- Veröffentlicht 09.07.2026 17:16:58
- Zuletzt bearbeitet 09.07.2026 19:03:47
A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulation results in use after free. The attack is only possible with local access. ...
CVE-2026-14618
- EPSS 0.32%
- Veröffentlicht 04.07.2026 06:00:09
- Zuletzt bearbeitet 06.07.2026 18:16:37
A vulnerability was detected in Open5GS up to 2.7.7. Affected by this vulnerability is the function amf_nnrf_handle_nf_discover of the file src/amf/nnrf-handler.c of the component AMF. The manipulation results in denial of service. The attack may be ...
CVE-2026-10565
- EPSS 0.22%
- Veröffentlicht 02.06.2026 01:30:09
- Zuletzt bearbeitet 22.07.2026 19:10:00
A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can ...
CVE-2026-10157
- EPSS 0.42%
- Veröffentlicht 31.05.2026 00:30:10
- Zuletzt bearbeitet 22.07.2026 07:10:00
A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication. It is possible to i...
CVE-2026-10156
- EPSS 0.28%
- Veröffentlicht 30.05.2026 23:45:09
- Zuletzt bearbeitet 22.07.2026 07:10:00
A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a manipulation of the argument nf_info_pool can lead to resource...
CVE-2026-10117
- EPSS 0.27%
- Veröffentlicht 30.05.2026 12:30:08
- Zuletzt bearbeitet 22.07.2026 06:10:00
A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The explo...