Description
A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.
Published: 2026-08-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Open5GS contains a vulnerability in the smf_gx_cca_cb function, part of the SMF Diameter Gx Credit‑Control‑Answer handler. A malformed or crafted carriage of this function can disrupt service, causing a denial of service. The weakness is identified as CWE‑404, indicating improper resource shutdown or release. The impact is limited to service availability; no confidentiality or integrity compromise is documented.

Affected Systems

The flaw affects all Open5GS deployments up to version 2.7.6. Version 2.7.7 and later contain a fix that resolves the issue. The vendor recommends upgrading to the latest release to eliminate the risk.

Risk and Exploitability

The CVSS score of 5.3 classifies the vulnerability as moderate in severity. The EPSS score of less than 1% suggests that exploitation attempts are rare, yet the public release of exploit code makes it a real risk. The flaw can be triggered remotely through Diameter Gx traffic, meaning an attacker does not need local access. The CVE is not listed in CISA’s KEV catalog, aligning with its moderate severity and low EPSS score.

Generated by OpenCVE AI on August 12, 2026 at 14:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Open5GS to version 2.7.7 or later to apply the restricted smf_gx_cca_cb logic that prevents the crash
  • If upgrading immediately is not feasible, recompile Open5GS with the patch commit f23d7a5e959acd8f37b925dc29b85f26b7d391cb applied to the smf_gx_cca_cb handler
  • Restrict incoming Diameter Gx Credit‑Control‑Answer traffic by configuring firewalls or service‑level filters to allow only trusted peers

Generated by OpenCVE AI on August 12, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.
Title Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-404
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-12T12:35:38.910Z

Reserved: 2026-08-09T17:50:46.986Z

Link: CVE-2025-15687

cve-icon Vulnrichment

Updated: 2026-08-12T12:35:35.983Z

cve-icon NVD

Status : Received

Published: 2026-08-12T04:17:38.617

Modified: 2026-08-12T13:17:18.720

Link: CVE-2025-15687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T14:30:03Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release