Open5gs
by Open5gs
Source repositories
CVEs (205)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34476 | Med | 0.00 | 5.3 | 0.01 | May 5, 2024 | Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len. | ||
| CVE-2024-34475 | Hig | 0.00 | 7.5 | 0.01 | May 5, 2024 | Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR. | ||
| CVE-2023-50020 | Hig | 0.00 | 7.5 | 0.01 | Jan 2, 2024 | An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF. | ||
| CVE-2023-50019 | Med | 0.00 | 5.9 | 0.01 | Jan 2, 2024 | An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response. | ||
| CVE-2022-3299 | Med | 0.00 | 4.3 | 0.01 | Sep 26, 2022 | A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched… |
- risk 0.00cvss 5.3epss 0.01
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
- risk 0.00cvss 7.5epss 0.01
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
- risk 0.00cvss 5.9epss 0.01
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
- risk 0.00cvss 4.3epss 0.01
A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched…
Page 11 of 11