Impact
Open5GS contains a vulnerability in the smf_gx_cca_cb function, part of the SMF Diameter Gx Credit‑Control‑Answer handler. A malformed or crafted carriage of this function can disrupt service, causing a denial of service. The weakness is identified as CWE‑404, indicating improper resource shutdown or release. The impact is limited to service availability; no confidentiality or integrity compromise is documented.
Affected Systems
The flaw affects all Open5GS deployments up to version 2.7.6. Version 2.7.7 and later contain a fix that resolves the issue. The vendor recommends upgrading to the latest release to eliminate the risk.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as moderate in severity. The EPSS score of less than 1% suggests that exploitation attempts are rare, yet the public release of exploit code makes it a real risk. The flaw can be triggered remotely through Diameter Gx traffic, meaning an attacker does not need local access. The CVE is not listed in CISA’s KEV catalog, aligning with its moderate severity and low EPSS score.
OpenCVE Enrichment