Open5GS
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*
- <= 2.7.5
A reachable assertion vulnerability has been identified in Open5GS versions through 2.7.5, specifically within the AMF service's PDU session handling function. The issue arises from improper state validation during the release of session management context, particularly when the system is in security mode. This flaw can lead to a fatal assertion failure, causing crashes in the AMF service. The vulnerability can be exploited locally by sending malformed NAS messages, disrupting core network availability.
Exploitation of this vulnerability causes the AMF service to crash, leading to a denial of service in the core network.
To reproduce this vulnerability, first ensure that all Open5GS network functions are running. Then, send a request to release the session management context while the system is in security mode. This can be done by replaying a specific seed that triggers the invalid state transition, causing the AMF to encounter an assertion failure.
Users are advised to update to Open5GS version 2.7.6 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.