Filtered by vendor Open5gs
Subscribe
Total
154 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-40129 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 9.8 CRITICAL |
| Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c. | |||||
| CVE-2024-34476 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 5.3 MEDIUM |
| Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len. | |||||
| CVE-2024-34475 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR. | |||||
| CVE-2024-34235 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 8.6 HIGH |
| Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service. | |||||
| CVE-2024-33382 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration | |||||
| CVE-2024-24432 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 5.3 MEDIUM |
| A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |||||
| CVE-2024-24431 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length. | |||||
| CVE-2024-24430 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |||||
| CVE-2024-24429 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 8.6 HIGH |
| A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet. | |||||
| CVE-2024-24428 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet. | |||||
| CVE-2024-24427 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet. | |||||
| CVE-2023-50020 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF. | |||||
| CVE-2023-50019 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 5.9 MEDIUM |
| An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response. | |||||
| CVE-2023-4885 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 6.5 MEDIUM |
| Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure of sensitive information. | |||||
| CVE-2023-4884 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 6.5 MEDIUM |
| An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication. | |||||
| CVE-2023-4883 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service by sending a specially crafted json string to the VNF (Virtual Network Function), and triggering the ogs_sbi_message_free function, which could cause a service outage. | |||||
| CVE-2023-4882 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash. | |||||
| CVE-2023-37023 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 8.6 HIGH |
| Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service. | |||||
| CVE-2023-37022 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 7.5 HIGH |
| Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service. | |||||
| CVE-2023-37021 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 8.6 HIGH |
| Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service. | |||||
