Vulnerabilities
Vulnerable Software
Open5gs:  >> Open5gs  Security Vulnerabilities
A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.
CVSS Score
7.5
EPSS Score
0.004
Published
2024-11-15
An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) session establishment process.
CVSS Score
7.5
EPSS Score
0.133
Published
2024-11-12
Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.
CVSS Score
9.8
EPSS Score
0.004
Published
2024-07-16
open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.
CVSS Score
9.8
EPSS Score
0.004
Published
2024-07-16
An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
CVSS Score
5.3
EPSS Score
0.002
Published
2024-05-08
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-05-05
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-05-05
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
CVSS Score
5.9
EPSS Score
0.003
Published
2024-01-02
An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-01-02
DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-10-03


Contact Us

Shodan ® - All rights reserved