VYPR

Open5gs

by Open5gs

Source repositories

CVEs (185)

  • CVE-2025-8803MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability has been found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to…

  • CVE-2025-8802MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was determined in Open5GS up to 2.7.5. This vulnerability affects the function smf_state_operational of the file src/smf/smf-sm.c of the component SMF. The manipulation of the argument stream leads to denial of service. The attack can be initiated remotely. The…

  • CVE-2025-8801MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.5. This affects the function gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2025-8800MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability has been found in Open5GS up to 2.7.5. Affected by this issue is the function esm_handle_pdn_connectivity_request of the file src/mme/esm-handler.c of the component AMF Component. The manipulation leads to denial of service. The attack may be launched remotely.…

  • CVE-2025-8799MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in Open5GS up to 2.7.5. Affected by this vulnerability is the function amf_npcf_am_policy_control_build_create/amf_nsmf_pdusession_build_create_sm_context of the file src/amf/npcf-build.c of the component AMF. The manipulation leads to denial of…

  • CVE-2025-7485LowJul 12, 2025
    risk 0.00cvss 3.3epss 0.00

    A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler of the component SCTP Partial Message Handler. The manipulation leads to reachable assertion. The attack…

  • CVE-2025-6952LowJul 1, 2025
    risk 0.00cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertion. It is possible to launch…

  • CVE-2025-44951HigJun 18, 2025
    risk 0.00cvss 7.1epss 0.00

    A missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dev` field with a value with length greater than 32.

  • CVE-2025-5935MedJun 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the component AMF/MME. The manipulation of the argument ran_ue_id leads to denial of…

  • CVE-2025-5520MedJun 3, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack…

  • CVE-2025-5501MedJun 3, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_request_transfer of the file src/smf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads…

  • CVE-2025-25774MedMar 12, 2025
    risk 0.00cvss 6.5epss 0.00

    An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).

  • CVE-2025-1925MedMar 4, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service. The…

  • CVE-2025-1893MedMar 4, 2025
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. The attack can be…

  • CVE-2024-56921HigFeb 3, 2025
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response.

  • CVE-2024-57519HigJan 28, 2025
    risk 0.00cvss 7.5epss 0.01

    An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.

  • CVE-2024-34476MedMay 5, 2024
    risk 0.00cvss 5.3epss 0.01

    Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.

  • CVE-2024-34475HigMay 5, 2024
    risk 0.00cvss 7.5epss 0.01

    Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.

  • CVE-2023-50020HigJan 2, 2024
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

  • CVE-2023-50019MedJan 2, 2024
    risk 0.00cvss 5.9epss 0.01

    An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.

Page 9 of 10