CVE-2026-7585
בינונית 4.3
תיאור (מקור, אנגלית)
A vulnerability was determined in Open5GS up to 2.7.7. The impacted element is the function amf_nudm_sdm_handle_provisioned of the file /src/amf/nudm-handler.c of the component AMF. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L - CVSS 4.0
-
2.1 (LOW)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-27/9/2026
- CWE
- CWE-404
מוצרים מושפעים
open5gs: open5gs
קישורים
- https://github.com/open5gs/open5gs/ Product
- https://github.com/open5gs/open5gs/issues/4403 Issue Tracking
- https://vuldb.com/submit/804334 Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/804335 Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/804337 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/360533 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/360533/cti Permissions RequiredVDB Entry
- https://vuldb.com/submit/804334 Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/804335 Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/804337 Third Party AdvisoryVDB Entry