Impact
A flaw in Open5GS up to version 2.7.1 exists in the freeDiameter component, where an attacker can manipulate an unknown functionality causing memory corruption. This vulnerability can be exploited remotely, potentially allowing the attacker to corrupt memory and compromise the integrity of the system or lead to arbitrary code execution.
Affected Systems
The affected vendor is Open5GS. All releases of Open5GS up to and including version 2.7.1 are vulnerable. No specific subcomponents or modules are further enumerated beyond the freeDiameter element. Companies running Open5GS servers must check whether their deployments use these affected versions.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score is less than 1%, suggesting a low probability of exploitation at the current time. Since the vulnerability is not listed in the CISA KEV catalog and the only listed attack vector is remote, the risk is moderate, but a memory corruption flaw in a core component may be a high-value target for attackers if they can locate affected instances. The CNA has not published a fix or workaround yet, so applying an update to a version newer than 2.7.1 is the only known mitigation.
OpenCVE Enrichment