Free5gc

Free5gc

68 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 23.01.2026 00:00:00
  • Zuletzt bearbeitet 11.02.2026 19:55:25

An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 07.01.2026 21:01:21

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversi...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 07.01.2026 21:00:58

An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 24.11.2025 00:00:00
  • Zuletzt bearbeitet 01.12.2025 16:14:56

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API.

  • EPSS 0.31%
  • Veröffentlicht 24.11.2025 00:00:00
  • Zuletzt bearbeitet 01.12.2025 16:16:12

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.

  • EPSS 0.21%
  • Veröffentlicht 24.11.2025 00:00:00
  • Zuletzt bearbeitet 01.12.2025 16:16:31

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 12.11.2025 19:15:37
  • Zuletzt bearbeitet 31.12.2025 16:12:47

free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 23.09.2025 18:15:35
  • Zuletzt bearbeitet 08.10.2025 17:56:44

Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 29.05.2025 00:00:00
  • Zuletzt bearbeitet 25.06.2025 15:43:17

Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components

Exploit
  • EPSS 1.04%
  • Veröffentlicht 22.12.2023 11:15:07
  • Zuletzt bearbeitet 21.11.2024 08:33:19

An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.