CVE-2025-41067

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service unavailable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

29 Oct 2025, 11:15

Type Values Removed Values Added
Summary (en) Reachable Assertion vulnerability in Open5GS up to version 2.7.5 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service unavailable. (en) Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service unavailable.
References
  • {'url': 'https://open5gs.org/open5gs/release/2025/03/30/release-v2.7.5.html', 'tags': ['Release Notes'], 'source': 'cve-coordination@incibe.es'}
  • () https://open5gs.org/open5gs/release/2025/07/19/release-v2.7.6.html -

28 Oct 2025, 13:09

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Open5gs
Open5gs open5gs
References () https://open5gs.org/open5gs/release/2025/03/30/release-v2.7.5.html - () https://open5gs.org/open5gs/release/2025/03/30/release-v2.7.5.html - Release Notes
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-newplanes-open5gs - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-newplanes-open5gs - Third Party Advisory
CPE cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

27 Oct 2025, 13:19

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-27 13:15

Updated : 2025-10-29 11:15


NVD link : CVE-2025-41067

Mitre link : CVE-2025-41067

CVE.ORG link : CVE-2025-41067


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-617

Reachable Assertion