Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55785

Опубликовано: 28 авг. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAkaComfirmRequestProcedure compares RES* and XRES* with strings.EqualFold and logs the expected XRES* value at INFO level before comparison. EapAuthComfirmRequestProcedure compares AT_MAC and XMAC with bytes.Equal and evaluates XRES == RES with ordinary string equality. These comparisons can return at mismatch-dependent times, although testing did not demonstrate a practical remote timing oracle because of HTTP/SBI timing noise. The INFO log exposes authentication material to operators, log collectors, sidecars, or processes able to read AUSF logs. This issue is fixed in version 1.4.5.

EPSS

Процентиль: 21%
0.00284
Низкий

3.7 Low

CVSS3

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 3.7
github
18 дней назад

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

EPSS

Процентиль: 21%
0.00284
Низкий

3.7 Low

CVSS3

Дефекты

CWE-208