CVE-2023-4882
- EPSS 0.52%
- Veröffentlicht 03.10.2023 15:15:40
- Zuletzt bearbeitet 21.11.2024 08:36:10
DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the s...
CVE-2023-4883
- EPSS 0.52%
- Veröffentlicht 03.10.2023 15:15:40
- Zuletzt bearbeitet 21.11.2024 08:36:10
Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ...
CVE-2023-4884
- EPSS 0.43%
- Veröffentlicht 03.10.2023 15:15:40
- Zuletzt bearbeitet 21.11.2024 08:36:11
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.
CVE-2023-4885
- EPSS 0.28%
- Veröffentlicht 03.10.2023 15:15:40
- Zuletzt bearbeitet 21.11.2024 08:36:11
Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure of sensitive information.
CVE-2023-23846
- EPSS 0.8%
- Veröffentlicht 01.02.2023 03:15:08
- Zuletzt bearbeitet 27.03.2025 14:15:20
Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages, a protocol payload with any extension header length set to zer...
CVE-2022-43221
- EPSS 0.85%
- Veröffentlicht 01.11.2022 14:15:15
- Zuletzt bearbeitet 02.05.2025 22:15:16
open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
CVE-2022-43222
- EPSS 0.85%
- Veröffentlicht 01.11.2022 14:15:15
- Zuletzt bearbeitet 02.05.2025 22:15:16
open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
CVE-2022-43223
- EPSS 0.85%
- Veröffentlicht 01.11.2022 14:15:15
- Zuletzt bearbeitet 02.05.2025 21:15:19
open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted UE attachment.
CVE-2022-40890
- EPSS 0.9%
- Veröffentlicht 29.09.2022 13:15:11
- Zuletzt bearbeitet 21.05.2025 14:15:25
A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.
CVE-2022-3354
- EPSS 0.8%
- Veröffentlicht 28.09.2022 16:15:12
- Zuletzt bearbeitet 21.11.2024 07:19:21
A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic. This vulnerability affects unknown code in the library lib/core/ogs-tlv-msg.c of the component UDP Packet Handler. The manipulation leads to denial of service. The ...