Impact
The Open5GS 2.7.7 deployment is vulnerable through a use‑after‑free condition in the amf_context_final function of the AMF component, as identified by CWE‑416 and CWE‑119. When a local attacker manipulates AMF context data, the vulnerability can lead to arbitrary code execution or cause the AMF process to crash. The CVSS score of 4.8 classifies the issue as medium severity, reflecting the limited scope and local nature of the attack. The public availability of an exploit emphasizes the need for timely remediation.
Affected Systems
Vulnerable systems are those running Open5GS Open5GS 2.7.7. Earlier releases that include the same amf_context_final code could also carry the flaw, but the CVE description specifically confirms the issue in version 2.7.7.
Risk and Exploitability
The exploit requires local access to the host where Open5GS is running; remote attackers are not directly affected. The EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because a public exploit was released, a local adversary with sufficient privileges can potentially gain control of the AMF process, which is critical to 5G core network operations.
OpenCVE Enrichment