Impact
The vulnerability is a heap‑based buffer overflow in the function mme_s6a_subscription_data_from_avp located in src/mme/mme-fd-path.c of the Open5GS Diameter S6a interface. By manipulating the msisdn_len argument, an attacker can overflow a heap buffer, potentially corrupting adjacent memory and leading to loss of data integrity or service disruption. The flaw is noted to be exploitable remotely.
Affected Systems
The flaw exists in Open5GS implementations up to and including version 2.7.1. The vendor recommends upgrading to version 2.7.2, which incorporates the fix identified by commit 7ea82cb87bb65c3694d8d7c7a5efed1c4d3c9304. No other versions are explicitly affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation does not require special privileges and can be performed remotely, so systems exposed to untrusted networks remain at risk until patched.
OpenCVE Enrichment