Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
The vulnerabilitiy has been fixed by the Open5GS team in version v2.7.6.
Workaround
No workaround given by the vendor.
Wed, 29 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 29 Oct 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reachable Assertion vulnerability in Open5GS up to version 2.7.5 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service unavailable. | Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service unavailable. |
| References |
|
Tue, 28 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open5gs
Open5gs open5gs |
|
| Vendors & Products |
Open5gs
Open5gs open5gs |
Mon, 27 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reachable Assertion vulnerability in Open5GS up to version 2.7.5 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service unavailable. | |
| Title | Reachable Assertion vulnerability in Open5GS | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-10-29T10:27:42.252Z
Reserved: 2025-04-16T09:09:34.457Z
Link: CVE-2025-41067
Updated: 2025-10-27T15:09:42.992Z
Status : Modified
Published: 2025-10-27T13:15:44.973
Modified: 2025-10-29T11:15:44.170
Link: CVE-2025-41067
No data.
OpenCVE Enrichment
Updated: 2025-10-27T22:03:41Z