Open5GS
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*
- <= 2.7.7
A denial-of-service vulnerability has been identified in Open5GS versions through 2.7.7, specifically within the NSSF component. The issue arises in the function 'ogs_sbi_discovery_option_add_service_names' located in the file '/lib/sbi/message.c'. The vulnerability can be exploited remotely, causing the NSSF process to crash. This issue has been publicly disclosed.
Exploitation of this vulnerability leads to a crash of the NSSF process, causing a denial-of-service condition on the affected component.
To reproduce this vulnerability, send a 'GET' request to the '/nnssf-nsselection/v2/network-slice-information' endpoint with an oversized 'service-names' query parameter. The NSSF will crash due to an assertion failure, as the number of service names exceeds the maximum allowed limit.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.