VYPR
Vendor

Open5gs

Products
5
CVEs
185
Across products
196
Status
Private

Products

5

Recent CVEs

185
View all 185 CVEs →
  • CVE-2024-40130CriJul 16, 2024
    risk 0.57cvss 9.8epss 0.01

    open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.

  • CVE-2024-40129CriJul 16, 2024
    risk 0.57cvss 9.8epss 0.00

    Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.

  • CVE-2021-25863HigJan 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.

  • CVE-2024-24429HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

  • CVE-2024-34235HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service.

  • CVE-2023-37023HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

  • CVE-2023-37021HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37020HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Complete` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting…

  • CVE-2023-37019HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of…

  • CVE-2023-37018HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37017HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of…

  • CVE-2023-37016HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37015HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Path Switch Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in…

  • CVE-2025-44952HigJun 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dnn` field with a value with length greater than 101.

  • CVE-2025-46115HigApr 30, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

  • CVE-2025-65559HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID…

  • CVE-2025-41068HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is achieved by sending the creation of an NF with an invalid type via SBI and then requesting its data. The NRF executes a check that…

  • CVE-2025-41067HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service…

  • CVE-2025-52322HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (PGW-C), using the IP address of a legitimate UE in the PDN Address Allocation (PAA) field

  • CVE-2025-29339HigApr 22, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value propagated from SMF (or via…