Free5gc

Free5gc

92 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.35%
  • Veröffentlicht 27.05.2026 15:50:18
  • Zuletzt bearbeitet 28.05.2026 18:30:58

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthorization/v1/app-sessions handler panics on a single authenticated request whose ascReqData.suppFeat == "1" (enabling traffic-routing ...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 27.05.2026 15:49:20
  • Zuletzt bearbeitet 28.05.2026 17:50:05

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot be reached. In PfdChangeNotifier.FlushNotifications(), the notifier calls Nne...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 27.05.2026 15:48:22
  • Zuletzt bearbeitet 28.05.2026 18:23:47

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A forged or arbitrary bearer token (e.g. Authorization: Bearer not-...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 27.05.2026 15:47:33
  • Zuletzt bearbeitet 28.05.2026 18:01:21

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /upi/v1/upNodesLinks create-or-update handler accepts attacker-controlled...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 27.05.2026 15:46:10
  • Zuletzt bearbeitet 28.05.2026 17:37:55

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a nil-pointer dereference when the upstream UDR call f...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 27.05.2026 15:45:14
  • Zuletzt bearbeitet 28.05.2026 17:02:32

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions handler contains a nil-pointer dereference reachable f...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 27.05.2026 15:44:27
  • Zuletzt bearbeitet 28.05.2026 16:52:20

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions handler panics on a single authenticated request again...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 27.05.2026 15:43:34
  • Zuletzt bearbeitet 28.05.2026 16:51:24

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug family. The handler in NFs/nrf/internal/sbi/api_accesstoken.go reflects ove...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 27.05.2026 15:41:38
  • Zuletzt bearbeitet 28.05.2026 16:25:38

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, ...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 27.05.2026 15:40:41
  • Zuletzt bearbeitet 28.05.2026 16:24:54

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route wi...