Open5gs
by Open5gs
Source repositories
CVEs (185)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3299 | Med | 0.00 | 4.3 | 0.01 | Sep 26, 2022 | A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched… | ||
| CVE-2021-44109 | Hig | 0.00 | 7.5 | 0.02 | Apr 5, 2022 | A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request. | ||
| CVE-2021-44108 | Hig | 0.00 | 7.5 | 0.01 | Apr 5, 2022 | A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf. | ||
| CVE-2021-45462 | Hig | 0.00 | 7.5 | 0.04 | Dec 23, 2021 | In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF. | ||
| CVE-2021-28122 | Cri | 0.00 | 9.8 | 0.04 | Mar 10, 2021 | A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative… |
- risk 0.00cvss 4.3epss 0.01
A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched…
- risk 0.00cvss 7.5epss 0.02
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.
- risk 0.00cvss 7.5epss 0.01
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.
- risk 0.00cvss 7.5epss 0.04
In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
- risk 0.00cvss 9.8epss 0.04
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative…
Page 10 of 10