CVE-2026-8266
בינונית 6.5
תיאור (מקור, אנגלית)
A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsm_build_pdu_session_establishment_accept of the file /src/smf/gsm-build.c of the component SMF. The manipulation results in denial of service. The attack can be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - CVSS 4.0
-
2.1 (LOW)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-2/8/2026
- CWE
- CWE-404
מוצרים מושפעים
open5gs: open5gs
קישורים
- https://github.com/open5gs/open5gs/issues/4447 ExploitIssue Tracking
- https://github.com/open5gs/open5gs/ Product
- https://vuldb.com/submit/808483 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362563 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362563/cti Permissions RequiredVDB Entry