VYPR
Vendor

Open5gs

Products
7
CVEs
205
Across products
232
Status
Private

Products

7

Recent CVEs

205
View all 205 CVEs →
  • CVE-2021-28122CriMar 10, 2021
    risk 0.64cvss 9.8epss 0.04

    A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative…

  • CVE-2024-40130CriJul 16, 2024
    risk 0.57cvss 9.8epss 0.01

    open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.

  • CVE-2024-40129CriJul 16, 2024
    risk 0.57cvss 9.8epss 0.00

    Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.

  • CVE-2021-25863HigJan 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.

  • CVE-2024-24429HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

  • CVE-2024-34235HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service.

  • CVE-2023-37023HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

  • CVE-2023-37021HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37020HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Complete` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting…

  • CVE-2023-37019HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of…

  • CVE-2023-37018HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37017HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of…

  • CVE-2023-37016HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37015HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Path Switch Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in…

  • CVE-2025-44952HigJun 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dnn` field with a value with length greater than 101.

  • CVE-2026-37198HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.01

    An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.

  • CVE-2026-71676HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain, triggered when the message type byte of a NAS PDU is mutated

  • CVE-2026-71675HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c

  • CVE-2025-46115HigApr 30, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

  • CVE-2025-65559HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID…