CVE-2025-25774

An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:2.7.2:*:*:*:*:*:*:*

History

29 Apr 2025, 15:04

Type Values Removed Values Added
References () https://github.com/guoweifk/BugReport/blob/main/Open5GS%20AMF%20Denial%20of%20Service%20via%20GMM%20State%20Handling%20in%20Handover - () https://github.com/guoweifk/BugReport/blob/main/Open5GS%20AMF%20Denial%20of%20Service%20via%20GMM%20State%20Handling%20in%20Handover - Exploit, Third Party Advisory
References () https://github.com/open5gs/open5gs/commit/2e68706f1eea029d5172ccad946e78b352c031d0 - () https://github.com/open5gs/open5gs/commit/2e68706f1eea029d5172ccad946e78b352c031d0 - Patch
References () https://github.com/open5gs/open5gs/issues/3671 - () https://github.com/open5gs/open5gs/issues/3671 - Exploit, Issue Tracking, Vendor Advisory
Summary
  • (es) Se detectó un problema en Open5GS v2.7.2. Cuando un UE conmuta entre dos gNB y envía una solicitud de transferencia en un momento específico, puede causar una excepción en la máquina de estados interna del AMF, lo que provoca un bloqueo del AMF y una denegación de servicio (DoS).
CWE NVD-CWE-noinfo
First Time Open5gs
Open5gs open5gs
CPE cpe:2.3:a:open5gs:open5gs:2.7.2:*:*:*:*:*:*:*

12 Mar 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-691

12 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 17:15

Updated : 2025-04-29 15:04


NVD link : CVE-2025-25774

Mitre link : CVE-2025-25774

CVE.ORG link : CVE-2025-25774


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
NVD-CWE-noinfo CWE-691

Insufficient Control Flow Management