Description
A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes memory corruption. The attack is possible to be carried out remotely.
Published: 2026-08-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Open5GS up to version 2.7.1 exists in the freeDiameter component, where an attacker can manipulate an unknown functionality causing memory corruption. This vulnerability can be exploited remotely, potentially allowing the attacker to corrupt memory and compromise the integrity of the system or lead to arbitrary code execution.

Affected Systems

The affected vendor is Open5GS. All releases of Open5GS up to and including version 2.7.1 are vulnerable. No specific subcomponents or modules are further enumerated beyond the freeDiameter element. Companies running Open5GS servers must check whether their deployments use these affected versions.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. The EPSS score is less than 1%, suggesting a low probability of exploitation at the current time. Since the vulnerability is not listed in the CISA KEV catalog and the only listed attack vector is remote, the risk is moderate, but a memory corruption flaw in a core component may be a high-value target for attackers if they can locate affected instances. The CNA has not published a fix or workaround yet, so applying an update to a version newer than 2.7.1 is the only known mitigation.

Generated by OpenCVE AI on August 12, 2026 at 14:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Open5GS to a release newer than 2.7.1.
  • If upgrading is not immediately possible, restrict external access to the Open5GS interfaces to trusted networks only, using firewall or network segmentation.
  • Monitor system logs for anomalous memory corruption symptoms and unexpected crashes associated with the freeDiameter component.

Generated by OpenCVE AI on August 12, 2026 at 14:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes memory corruption. The attack is possible to be carried out remotely.
Title Open5GS freeDiameter memory corruption
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-119
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-12T12:36:27.461Z

Reserved: 2026-08-09T17:44:47.596Z

Link: CVE-2025-15685

cve-icon Vulnrichment

Updated: 2026-08-12T12:36:23.765Z

cve-icon NVD

Status : Received

Published: 2026-08-12T03:16:42.420

Modified: 2026-08-12T13:17:17.577

Link: CVE-2025-15685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T15:30:02Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer