Open5GS
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*
- <= 2.7.7
A denial-of-service vulnerability has been identified in Open5GS versions through 2.7.7, specifically within the NRF component. The issue arises in the function yuarel_parse, located in the library /lib/sbi/conv.c. When an invalid 'hnrf-uri' is provided, it leads to a null dereference, causing the NRF process to crash. This vulnerability can be exploited remotely.
Exploitation of this vulnerability causes the NRF process to terminate unexpectedly, leading to a crash.
The vulnerability can be reproduced by sending a GET request to the '/nnrf-disc/v1/nf-instances' endpoint with an invalid 'hnrf-uri' parameter, along with 'target-plmn-list' and 'requester-plmn-list' parameters. The NRF process will then crash due to a null dereference.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.