Impact
A flaw in the Open5GS HSS Service involves a missing resource deallocation (CWE-404) when an attacker manipulates the Session-Id argument to the fd_msg_sess_get function, causing the service to crash and become unavailable. The vulnerability is rated moderate with a CVSS score of 5.3 and is exploitable remotely.
Affected Systems
The issue affects Open5GS HSS Service implementations up to and including version 2.7.6. Users running any of these releases should assess whether they expose the HSS service to external networks.
Risk and Exploitability
The EPSS score is reported to be below 1%, indicating a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. However, because the impact is denial‑of‑service and the attack can be conducted remotely, administrators should consider the risk moderate and take timely action to prevent potential outages.
OpenCVE Enrichment