VYPR

Open5gs

by Open5gs

Source repositories

CVEs (185)

  • CVE-2024-24430HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2023-37022HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

  • CVE-2023-37014HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting…

  • CVE-2024-24428HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.00

    A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

  • CVE-2024-24427HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.00

    A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2024-24431HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.

  • CVE-2024-51179HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) session establishment process.

  • CVE-2023-4883HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ogs_sbi_message_free…

  • CVE-2023-4882HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.01

    DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.

  • CVE-2023-23846HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages, a protocol payload with any extension header length set to zero causes an infinite loop.…

  • CVE-2022-43223HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted UE attachment.

  • CVE-2022-43222HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

  • CVE-2022-43221HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

  • CVE-2022-40890HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.

  • CVE-2022-39063HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Response. Once UPF receives a request, it gets the f_teid_len from incoming message, and then uses it to copy data from incoming message to struct…

  • CVE-2021-44081HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.

  • CVE-2021-41794HigOct 7, 2021
    risk 0.49cvss 7.5epss 0.01

    ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character is interpreted as a…

  • CVE-2023-37013HigJan 22, 2025
    risk 0.47cvss 7.3epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state…

  • CVE-2025-29646HigJun 18, 2025
    risk 0.46cvss 7.1epss 0.00

    An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest packet with restoration indication = true and (teid = 0 or teid >= ogs_pfcp_pdr_teid_pool.size).

  • CVE-2025-56568HigApr 30, 2026
    risk 0.42cvss 7.5epss 0.00

    Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Function) component of Open5GS before v2.7.5 allows remote attackers to cause denial of service via specially crafted NGAP messages containing malformed length…

Page 2 of 10