Description
A vulnerability was determined in omec-project amf up to 2.1.1. This issue affects the function RRCInactiveTransitionReport of the component NGAP Message Handler. Executing a manipulation can lead to denial of service. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called 34bc6724acc97dba1f8691e586da95b042cb612d. A patch should be applied to remediate this issue.
Published: 2026-07-04
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the omec-project AMF’s NGAP Message Handler was identified in the RRCInactiveTransitionReport routine. The official description indicates that a crafted manipulation of this routine can result in a denial of service. The specific mechanics of the failure the associated CWE-404 suggests improper resource management. The vulnerability can be triggered remotely via NGAP traffic.

Affected Systems

All omec-project AMF releases up to version 2.1.1 are affected unless the bug fix from 34bc6724acc97dba1f8691e586da95b042cb612d has been applied. No other vendors.

Risk and Exploitability

CVSS scoring of 5.3 indicates moderate severity, while an EPSS score of less than 1 % implies that real‑world exploitation is currently unlikely. The vulnerability is not listedV catalog. The description confirms that the attack can be carried out remotely and that a public exploit is available, so an attacker could repeatedly send malformed NGAP messages to destabilize the AMF. No local privileges or elevated permissions are required.

Generated by OpenCVE AI on July 24, 2026 at 10:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch corresponding to commit 34bc6724acc97dba1f8691e586da95b042cb612d to the AMF codebase or upgrade to a newer release that includes the fix
  • Enable strict validation of RRCInactiveTransitionReport messages and configure NGAP connection limits to mitigate the impact of malformed packets
  • Implement network‑level filtering to limit NGAP traffic applied, helping to prevent repeated malformed message attempts.

Generated by OpenCVE AI on July 24, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 04 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in omec-project amf up to 2.1.1. This issue affects the function RRCInactiveTransitionReport of the component NGAP Message Handler. Executing a manipulation can lead to denial of service. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called 34bc6724acc97dba1f8691e586da95b042cb612d. A patch should be applied to remediate this issue.
Title omec-project amf NGAP Message RRCInactiveTransitionReport denial of service
First Time appeared Omec-project
Omec-project amf
Weaknesses CWE-404
CPEs cpe:2.3:a:omec-project:amf:*:*:*:*:*:*:*:*
Vendors & Products Omec-project
Omec-project amf
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Omec-project Amf
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-06T15:01:50.499Z

Reserved: 2026-07-03T17:01:00.787Z

Link: CVE-2026-14623

cve-icon Vulnrichment

Updated: 2026-07-06T15:01:47.016Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T10:15:02Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release