Impact
A buffer overflow occurs in the Open5GS Diameter Rx Handler when the parameters num_of_media_component and num_of_sub are manipulated in the function pcrf_rx_aar_cb. This flaw can corrupt memory and potentially allow an attacker to execute arbitrary code, compromising the confidentiality, integrity, and availability of the affected system. The weakness corresponds to the classic buffer overflow class of vulnerabilities (CWE-119, CWE-120).
Affected Systems
The vulnerability affects Open5GS versions up to 2.7.1. All deployments running these or older releases of the Open5GS Diameter Rx component are potentially exposed. Version 2.7.2 includes the patch identified by commit 87b4e4535c77ded627cdb6f4e4e2e3ea761f40b7, which resolves the overflow.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% reflects a very low estimated exploitation probability at this time. Based on the description, it is inferred that the flaw can be triggered remotely through a crafted Diameter AAR request, and the exploit code is publicly available, though the vulnerability is not listed in CISA’s KEV catalogue.
OpenCVE Enrichment