A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_request_transfer of the file src/smf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to reachable assertion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named 2daa44adab762c47a8cef69cc984946973a845b3. It is recommended to apply a patch to fix this issue.
References
Link | Resource |
---|---|
https://github.com/open5gs/open5gs/commit/2daa44adab762c47a8cef69cc984946973a845b3 | Patch |
https://github.com/open5gs/open5gs/issues/3909 | Exploit Issue Tracking Vendor Advisory |
https://github.com/open5gs/open5gs/issues/3909#issuecomment-2926682623 | Issue Tracking Vendor Advisory |
https://github.com/user-attachments/files/20362183/AMF.crash.due.to.pathswitchrequest.zip | Not Applicable |
https://vuldb.com/?ctiid.310915 | Permissions Required VDB Entry |
https://vuldb.com/?id.310915 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.582265 | Third Party Advisory VDB Entry |
https://github.com/open5gs/open5gs/issues/3909 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
13 Jun 2025, 19:36
Type | Values Removed | Values Added |
---|---|---|
First Time |
Open5gs
Open5gs open5gs |
|
References | () https://github.com/open5gs/open5gs/commit/2daa44adab762c47a8cef69cc984946973a845b3 - Patch | |
References | () https://github.com/open5gs/open5gs/issues/3909 - Exploit, Issue Tracking, Vendor Advisory | |
References | () https://github.com/open5gs/open5gs/issues/3909#issuecomment-2926682623 - Issue Tracking, Vendor Advisory | |
References | () https://github.com/user-attachments/files/20362183/AMF.crash.due.to.pathswitchrequest.zip - Not Applicable | |
References | () https://vuldb.com/?ctiid.310915 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.310915 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.582265 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* |
04 Jun 2025, 14:54
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Jun 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/open5gs/open5gs/issues/3909 - |
03 Jun 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-03 14:15
Updated : 2025-06-13 19:36
NVD link : CVE-2025-5501
Mitre link : CVE-2025-5501
CVE.ORG link : CVE-2025-5501
JSON object : View
Products Affected
open5gs
- open5gs
CWE
CWE-617
Reachable Assertion