Free5gc

Free5gc

92 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.4%
  • Veröffentlicht 12.11.2025 19:15:37
  • Zuletzt bearbeitet 31.12.2025 16:12:47

free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 23.09.2025 18:15:35
  • Zuletzt bearbeitet 08.10.2025 17:56:44

Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 29.05.2025 00:00:00
  • Zuletzt bearbeitet 25.06.2025 15:43:17

Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components

Exploit
  • EPSS 1.04%
  • Veröffentlicht 22.12.2023 11:15:07
  • Zuletzt bearbeitet 21.11.2024 08:33:19

An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 16.11.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:29:38

An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.

Exploit
  • EPSS 0.74%
  • Veröffentlicht 15.11.2023 22:15:27
  • Zuletzt bearbeitet 21.11.2024 08:30:10

Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.

Exploit
  • EPSS 0.85%
  • Veröffentlicht 15.11.2023 22:15:27
  • Zuletzt bearbeitet 21.11.2024 08:30:10

Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat message whose Recovery Time Stamp IE length is mutated to zero.

Exploit
  • EPSS 0.78%
  • Veröffentlicht 13.11.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 08:30:10

Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages.

  • EPSS 0.33%
  • Veröffentlicht 02.10.2023 15:15:15
  • Zuletzt bearbeitet 21.11.2024 08:35:37

Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE ...

Exploit
  • EPSS 0.73%
  • Veröffentlicht 18.11.2022 23:15:20
  • Zuletzt bearbeitet 30.04.2025 14:15:24

In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.