VYPR

Vendor CVEs

Open5gs

All CVEs

185 total · sorted by risk
  • CVE-2024-40130CriJul 16, 2024
    risk 0.57cvss 9.8epss 0.01

    open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.

  • CVE-2024-40129CriJul 16, 2024
    risk 0.57cvss 9.8epss 0.00

    Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.

  • CVE-2021-25863HigJan 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.

  • CVE-2024-24429HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

  • CVE-2024-34235HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service.

  • CVE-2023-37023HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

  • CVE-2023-37021HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37020HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Complete` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting…

  • CVE-2023-37019HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of…

  • CVE-2023-37018HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37017HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of…

  • CVE-2023-37016HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,…

  • CVE-2023-37015HigJan 22, 2025
    risk 0.56cvss 8.6epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Path Switch Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in…

  • CVE-2025-44952HigJun 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dnn` field with a value with length greater than 101.

  • CVE-2025-46115HigApr 30, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

  • CVE-2025-65559HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID…

  • CVE-2025-41068HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is achieved by sending the creation of an NF with an invalid type via SBI and then requesting its data. The NRF executes a check that…

  • CVE-2025-41067HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service…

  • CVE-2025-52322HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (PGW-C), using the IP address of a legitimate UE in the PDN Address Allocation (PAA) field

  • CVE-2025-29339HigApr 22, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value propagated from SMF (or via…

  • CVE-2024-24430HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2023-37022HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

  • CVE-2023-37014HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting…

  • CVE-2024-24428HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.00

    A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

  • CVE-2024-24427HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.00

    A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2024-24431HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.

  • CVE-2024-51179HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) session establishment process.

  • CVE-2023-4883HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ogs_sbi_message_free…

  • CVE-2023-4882HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.01

    DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.

  • CVE-2023-23846HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages, a protocol payload with any extension header length set to zero causes an infinite loop.…

  • CVE-2022-43223HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted UE attachment.

  • CVE-2022-43222HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

  • CVE-2022-43221HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

  • CVE-2022-40890HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.

  • CVE-2022-39063HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Response. Once UPF receives a request, it gets the f_teid_len from incoming message, and then uses it to copy data from incoming message to struct…

  • CVE-2021-44081HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.

  • CVE-2021-41794HigOct 7, 2021
    risk 0.49cvss 7.5epss 0.01

    ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character is interpreted as a…

  • CVE-2023-37013HigJan 22, 2025
    risk 0.47cvss 7.3epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state…

  • CVE-2025-29646HigJun 18, 2025
    risk 0.46cvss 7.1epss 0.00

    An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest packet with restoration indication = true and (teid = 0 or teid >= ogs_pfcp_pdr_teid_pool.size).

  • CVE-2025-56568HigApr 30, 2026
    risk 0.42cvss 7.5epss 0.00

    Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Function) component of Open5GS before v2.7.5 allows remote attackers to cause denial of service via specially crafted NGAP messages containing malformed length…

  • CVE-2026-0622MedJan 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset

  • CVE-2023-4885MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.00

    Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure of sensitive information.

  • CVE-2023-4884MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.00

    An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.

  • CVE-2023-37011MedJan 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial…

  • CVE-2023-37010MedJan 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `eNB Status Transfer` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in…

  • CVE-2023-37009MedJan 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in…

  • CVE-2026-10157HigMay 31, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.…

  • CVE-2025-15555HigFeb 4, 2026
    risk 0.40cvss 7.3epss 0.01

    A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LEN results in stack-based buffer…

  • CVE-2026-8187MedMay 9, 2026
    risk 0.35cvss 5.3epss 0.01

    A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. The project was informed of the…

  • CVE-2026-2521MedFeb 15, 2026
    risk 0.35cvss 5.3epss 0.01

    A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_response of the component SGW-C. Executing a manipulation can lead to memory corruption. The attack may be performed from remote. The exploit has been made…

Page 1 of 4