Описание
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
Ссылки
- Release NotesVendor Advisory
- Issue TrackingVendor Advisory
- Release NotesVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.7.1 (исключая)
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00082
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-805
Связанные уязвимости
CVSS3: 5.3
debian
почти 2 года назад
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can c ...
CVSS3: 5.3
github
почти 2 года назад
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
EPSS
Процентиль: 24%
0.00082
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-805