Open5GS Denial-of-Service Vulnerability in AMF Component

Vulnerability

A denial-of-service vulnerability has been identified in Open5GS versions through 2.7.2, specifically within the Access and Mobility Management Function (AMF) module. The issue arises in the function responsible for handling updates to the session management context, located in the file 'src/amf/nsmf-handler.c'. This vulnerability allows a single user equipment (UE) device to crash the AMF, leading to a complete disruption of mobility and session management services across the network. As a result, all connected UEs lose connectivity, and new registrations are blocked until the AMF is manually restarted. The vulnerability can be exploited remotely, without any authentication, and has been publicly disclosed along with a proof-of-concept exploit.

Impact

Exploitation of this vulnerability causes the AMF to crash, resulting in a total loss of 5G core network services. This disruption affects all connected users, who will lose connectivity, while new registration requests are blocked until the AMF is restarted. This vulnerability poses a critical risk to the reliability of 5G networks, particularly in commercial deployments.

Reproduction

The vulnerability can be reproduced by simulating a UE device that repeatedly connects and disconnects from the network. This can be done using the open-source UERANSIM tool, which simulates UE behavior. The AMF will crash after approximately 5 to 10 minutes of this repeated disconnection and reconnection, disrupting all network services.

Remediation

Users are advised to update to the latest version of Open5GS, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.