Impact
A flaw in Open5GS versions up to 2.7.7 allows an attacker to trigger a denial of service by manipulating the ogs_sbi_xact_add function in ogs-timer.c. The attack can be launched remotely. The vulnerability leads to a service interruption of the u-e-authentications endpoint, compromising availability and possibly denying new user authentications.
Affected Systems
The issue is confined to the Open5GS project, specifically the u-e-authentications endpoint component. All deployments running Open5GS 2.7.7 or earlier are affected. The CPE string confirms that the vulnerable library resides in the open5gs:open5gs package.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity; the EPSS score is currently not available, and the vulnerability is not listed in CISA KEV. The attacker can trigger the denial remotely, and a public exploit is already available. Because the flaw affects a critical authentication pathway, it can disrupt service for end users. The absence of an active KEV listing suggests a lower immediate threat but ongoing monitoring is still prudent.
OpenCVE Enrichment