VYPR

Vendor CVEs

Open5gs

All CVEs

185 total · sorted by risk
  • CVE-2025-15532MedJan 17, 2026
    risk 0.00cvss 5.3epss 0.01

    A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consumption. The attack may be performed from remote. The exploit has been released to the public and may…

  • CVE-2025-15529MedJan 16, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_response of the file src/sgwc/s5c-handler.c. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit…

  • CVE-2025-15528MedJan 16, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the component GTPv2 Bearer Response Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to…

  • CVE-2025-15176MedDec 29, 2025
    risk 0.00cvss 5.3epss 0.01

    A flaw has been found in Open5GS up to 2.7.5. This affects the function decode_ipv6_header/ogs_pfcp_pdr_rule_find_by_packet of the file lib/pfcp/rule-match.c of the component PFCP Session Establishment Request Handler. Executing a manipulation can lead to reachable assertion. It…

  • CVE-2025-63288HigNov 10, 2025
    risk 0.00cvss 7.5epss 0.00

    In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.

  • CVE-2025-55904MedSep 17, 2025
    risk 0.00cvss 4.0epss 0.00

    Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference when a multipart/related HTTP POST request with an empty HTTP body is sent to the SBI of either AMF, AUSF, BSF, NRF, NSSF, PCF, SMF, UDM, or UDR, resulting in a…

  • CVE-2025-52288HigSep 8, 2025
    risk 0.00cvss 7.5epss 0.00

    Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) component, in Open5GS thru 2.7.5 allowing attackers to cause a denial of service or other unspecified impacts via repeated UE connect…

  • CVE-2025-9405MedAug 25, 2025
    risk 0.00cvss 5.3epss 0.01

    A security flaw has been discovered in Open5GS up to 2.7.5. The impacted element is the function gmm_state_exception of the file src/amf/gmm-sm.c. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit has been released to the…

  • CVE-2025-8805MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was determined in Open5GS up to 2.7.5. Affected by this issue is the function smf_gsm_state_wait_pfcp_deletion of the file src/smf/gsm-sm.c of the component SMF. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has…

  • CVE-2025-8804MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ngap_build_downlink_nas_transport of the component AMF. The manipulation leads to reachable assertion. The attack can be launched remotely. The exploit has been disclosed to the…

  • CVE-2025-8803MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability has been found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to…

  • CVE-2025-8802MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was determined in Open5GS up to 2.7.5. This vulnerability affects the function smf_state_operational of the file src/smf/smf-sm.c of the component SMF. The manipulation of the argument stream leads to denial of service. The attack can be initiated remotely. The…

  • CVE-2025-8801MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.5. This affects the function gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2025-8800MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability has been found in Open5GS up to 2.7.5. Affected by this issue is the function esm_handle_pdn_connectivity_request of the file src/mme/esm-handler.c of the component AMF Component. The manipulation leads to denial of service. The attack may be launched remotely.…

  • CVE-2025-8799MedAug 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in Open5GS up to 2.7.5. Affected by this vulnerability is the function amf_npcf_am_policy_control_build_create/amf_nsmf_pdusession_build_create_sm_context of the file src/amf/npcf-build.c of the component AMF. The manipulation leads to denial of…

  • CVE-2025-7485LowJul 12, 2025
    risk 0.00cvss 3.3epss 0.00

    A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler of the component SCTP Partial Message Handler. The manipulation leads to reachable assertion. The attack…

  • CVE-2025-6952LowJul 1, 2025
    risk 0.00cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertion. It is possible to launch…

  • CVE-2025-44951HigJun 18, 2025
    risk 0.00cvss 7.1epss 0.00

    A missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attacker to cause a Buffer Overflow by changing the `session.dev` field with a value with length greater than 32.

  • CVE-2025-5935MedJun 10, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the component AMF/MME. The manipulation of the argument ran_ue_id leads to denial of…

  • CVE-2025-5520MedJun 3, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack…

  • CVE-2025-5501MedJun 3, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_request_transfer of the file src/smf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads…

  • CVE-2025-25774MedMar 12, 2025
    risk 0.00cvss 6.5epss 0.00

    An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).

  • CVE-2025-1925MedMar 4, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service. The…

  • CVE-2025-1893MedMar 4, 2025
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. The attack can be…

  • CVE-2024-56921HigFeb 3, 2025
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response.

  • CVE-2024-57519HigJan 28, 2025
    risk 0.00cvss 7.5epss 0.01

    An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.

  • CVE-2024-34476MedMay 5, 2024
    risk 0.00cvss 5.3epss 0.01

    Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.

  • CVE-2024-34475HigMay 5, 2024
    risk 0.00cvss 7.5epss 0.01

    Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.

  • CVE-2023-50020HigJan 2, 2024
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

  • CVE-2023-50019MedJan 2, 2024
    risk 0.00cvss 5.9epss 0.01

    An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.

  • CVE-2022-3299MedSep 26, 2022
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched…

  • CVE-2021-44109HigApr 5, 2022
    risk 0.00cvss 7.5epss 0.02

    A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.

  • CVE-2021-44108HigApr 5, 2022
    risk 0.00cvss 7.5epss 0.01

    A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.

  • CVE-2021-45462HigDec 23, 2021
    risk 0.00cvss 7.5epss 0.04

    In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.

  • CVE-2021-28122CriMar 10, 2021
    risk 0.00cvss 9.8epss 0.04

    A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative…

Page 4 of 4