CVE-2024-14042
- EPSS 0.48%
- Veröffentlicht 11.08.2026 19:15:09
- Zuletzt bearbeitet 12.08.2026 20:59:21
A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Diameter S6a Interface. Performing a manipulation of the argument os.len r...
CVE-2026-15720
- EPSS 0.37%
- Veröffentlicht 14.07.2026 19:16:51
- Zuletzt bearbeitet 15.07.2026 20:58:48
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
CVE-2026-15194
- EPSS 0.12%
- Veröffentlicht 09.07.2026 17:16:58
- Zuletzt bearbeitet 03.09.2026 04:15:09
A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulation results in use after free. The attack is only possible with local access. ...
CVE-2026-14618
- EPSS 0.32%
- Veröffentlicht 04.07.2026 06:00:09
- Zuletzt bearbeitet 06.07.2026 18:16:37
A vulnerability was detected in Open5GS up to 2.7.7. Affected by this vulnerability is the function amf_nnrf_handle_nf_discover of the file src/amf/nnrf-handler.c of the component AMF. The manipulation results in denial of service. The attack may be ...
CVE-2026-10565
- EPSS 0.22%
- Veröffentlicht 02.06.2026 01:30:09
- Zuletzt bearbeitet 22.07.2026 19:10:00
A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can ...
CVE-2026-10157
- EPSS 0.42%
- Veröffentlicht 31.05.2026 00:30:10
- Zuletzt bearbeitet 22.07.2026 07:10:00
A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication. It is possible to i...
CVE-2026-10156
- EPSS 0.28%
- Veröffentlicht 30.05.2026 23:45:09
- Zuletzt bearbeitet 22.07.2026 07:10:00
A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a manipulation of the argument nf_info_pool can lead to resource...
CVE-2026-10117
- EPSS 0.27%
- Veröffentlicht 30.05.2026 12:30:08
- Zuletzt bearbeitet 22.07.2026 06:10:00
A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The explo...
CVE-2026-10116
- EPSS 0.39%
- Veröffentlicht 30.05.2026 11:00:11
- Zuletzt bearbeitet 22.07.2026 06:10:00
A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications Endpoint. Performing a manipulation results in denial of ser...
CVE-2026-10115
- EPSS 0.31%
- Veröffentlicht 30.05.2026 10:15:07
- Zuletzt bearbeitet 22.07.2026 06:10:00
A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such manipulation leads to denial of service. The attack can be launched remotely. Th...