Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown

CVE-2024-24428

Disclosure Date: January 21, 2025 (last updated January 25, 2025)
A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.
Attacker Value
Unknown

CVE-2024-24427

Disclosure Date: January 21, 2025 (last updated January 25, 2025)
A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
Attacker Value
Unknown

CVE-2024-40130

Disclosure Date: July 16, 2024 (last updated August 22, 2024)
open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.
Attacker Value
Unknown

CVE-2024-40129

Disclosure Date: July 16, 2024 (last updated August 22, 2024)
Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.
Attacker Value
Unknown

CVE-2023-50020

Disclosure Date: January 02, 2024 (last updated January 12, 2024)
An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
Attacker Value
Unknown

CVE-2023-50019

Disclosure Date: January 02, 2024 (last updated January 12, 2024)
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
Attacker Value
Unknown

CVE-2023-4885

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure of sensitive information.
Attacker Value
Unknown

CVE-2023-4884

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.
Attacker Value
Unknown

CVE-2023-4883

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ogs_sbi_message_free function, which could cause a service outage.
Attacker Value
Unknown

CVE-2023-4882

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.