Impact
A flaw was discovered in the NGSetupRequest handler of omec-project AMF, located in handler.go. Manipulating an unknown internal function of this handler causes a denial‑of‑service condition by triggering a crash or hanging the service. The vulnerability is classified under CWE‑404, indicating an improper release of a resource. Attackers can exploit this weakness remotely by sending crafted requests to the NGSetupRequest endpoint, as the exploit is publicly available.
Affected Systems
The weakness affects omec-project AMF releases up to version 2.0.2 and 2.1.1. Systems running any of these releases without applying the patch identified by commit 34bc6724acc97dba1f8691e586da95b042cb612d are vulnerable. The affected component is the NGSetupRequest handler in the AMF module of omec-project.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium severity tier. An EPSS score of <1% signals a low perceived exploitation likelihood, yet the existence of a publicly available exploit suggests that real‑world usage may be higher. The attack vector is remote and requires only network access to the NGSetupRequest endpoint. The vulnerability is not listed in CISA's KEV catalog.
OpenCVE Enrichment