CVE-2026-8251
בינונית 6.5
תיאור (מקור, אנגלית)
A vulnerability was found in Open5GS up to 2.7.7. This impacts the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - CVSS 4.0
-
2.1 (LOW)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-2/8/2026
- CWE
- CWE-404
מוצרים מושפעים
open5gs: open5gs
קישורים
- https://github.com/open5gs/open5gs/issues/4445 ExploitIssue Tracking
- https://github.com/open5gs/open5gs/ Product
- https://vuldb.com/submit/808480 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362548 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362548/cti Permissions RequiredVDB Entry