VYPR
Medium severity5.3NVD Advisory· Published Mar 16, 2026· Updated Jun 17, 2026

CVE-2026-4240

CVE-2026-4240

Description

A vulnerability was determined in Open5GS up to 2.7.6. The affected element is the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6b_aaa_cb/smf_s6b_sta_cb of the component CCA Handler. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.7.7 is sufficient to fix this issue. Patch name: 80eb484a6ab32968e755e628b70d1a9c64f012ec. Upgrading the affected component is recommended.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Open5gs/Open5gs2 versions
    cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*range: <2.7.7
    • (no CPE)range: <=2.7.6

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.