Impact
A flaw in the amf_nnrf_handle_nf_discover function of the Open5GS AMF component allows a malformed NF discovery request to cause the application to crash, resulting in a denial of service. The weakness is classified as CWE‑404, indicating a missing resource or object management issue within the AMF application layer.
Affected Systems
The vulnerability affects the Open5GS AMF implementation up to version 2.7.7. Any deployment of Open5GS running these or earlier releases is susceptible, as the crash occurs within the AMF application code that handles NF discovery messages.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, while an EPSS score of <1% indicates a very low but non‑zero likelihood of exploitation. The exploit is publicly available and can be launched remotely, increasing risk for operators that expose the AMF service. The vulnerability is not listed in the CISA KEV catalog at this time, but it remains a concern for environments that rely on Open5GS for core network functionality.
OpenCVE Enrichment