An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54723 | An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication. |
Fixes
Solution
Open5GS is working on a fix for the reported vulnerabilities.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-19T19:55:50.558Z
Reserved: 2023-09-11T09:31:24.278Z
Link: CVE-2023-4884
Updated: 2024-08-02T07:38:01.041Z
Status : Modified
Published: 2023-10-03T15:15:40.593
Modified: 2024-11-21T08:36:11.070
Link: CVE-2023-4884
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD