Impact
A flaw in the omec-project AMF’s NGAP Message Handler was identified in the RRCInactiveTransitionReport routine. The official description indicates that a crafted manipulation of this routine can result in a denial of service. The specific mechanics of the failure the associated CWE-404 suggests improper resource management. The vulnerability can be triggered remotely via NGAP traffic.
Affected Systems
All omec-project AMF releases up to version 2.1.1 are affected unless the bug fix from 34bc6724acc97dba1f8691e586da95b042cb612d has been applied. No other vendors.
Risk and Exploitability
CVSS scoring of 5.3 indicates moderate severity, while an EPSS score of less than 1 % implies that real‑world exploitation is currently unlikely. The vulnerability is not listedV catalog. The description confirms that the attack can be carried out remotely and that a public exploit is available, so an attacker could repeatedly send malformed NGAP messages to destabilize the AMF. No local privileges or elevated permissions are required.
OpenCVE Enrichment