CVE-2025-60638
- EPSS 0.16%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:14:56
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API.
CVE-2025-60633
- EPSS 0.16%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:16:12
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.
CVE-2025-60632
- EPSS 0.11%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:16:31
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.
CVE-2025-63679
- EPSS 0.07%
- Veröffentlicht 12.11.2025 19:15:37
- Zuletzt bearbeitet 31.12.2025 16:12:47
free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.
CVE-2025-56394
- EPSS 0.08%
- Veröffentlicht 23.09.2025 18:15:35
- Zuletzt bearbeitet 08.10.2025 17:56:44
Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.
CVE-2025-29632
- EPSS 0.24%
- Veröffentlicht 29.05.2025 00:00:00
- Zuletzt bearbeitet 25.06.2025 15:43:17
Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components
CVE-2023-49391
- EPSS 3.13%
- Veröffentlicht 22.12.2023 11:15:07
- Zuletzt bearbeitet 21.11.2024 08:33:19
An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.
CVE-2023-47025
- EPSS 0.05%
- Veröffentlicht 16.11.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:29:38
An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.
CVE-2023-47347
- EPSS 0.08%
- Veröffentlicht 15.11.2023 22:15:27
- Zuletzt bearbeitet 21.11.2024 08:30:10
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.
CVE-2023-47345
- EPSS 0.25%
- Veröffentlicht 15.11.2023 22:15:27
- Zuletzt bearbeitet 21.11.2024 08:30:10
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat message whose Recovery Time Stamp IE length is mutated to zero.