Impact
The vulnerability arises in the CER Handler component of Open5GS, specifically within the diam_log_func function in lib/diameter/common/init.c. An attacker can manipulate input to trigger a reachable assertion that causes the component to crash. The resulting denial of service exposes the system to potential service disruption. The CVE description indicates that this flaw can be exploited remotely and that the exploit code is publicly available.
Affected Systems
This issue affects all installations of Open5GS up to and including version 2.7.6. The vulnerability has been fixed in version 2.7.7, which includes the patch identified by commit c1a803516a3c0485696cb9bcca7a80ad857c7383. All users of the Open5GS Open5GS product should review their deployment versions and ensure they are running the corrected release.
Risk and Exploitability
The CVSS score of 6.9 classifies the flaw as a moderate‑severity problem, but the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog and the attack vector is remote. The combination of a reachable assertion and potential for service crash means that an attacker who successfully triggers the condition could cause the impacted service to become unavailable, impacting availability for connected users and potentially affecting the overall reliability of the network infrastructure.
OpenCVE Enrichment