Impact
Open5GS versions up to 2.7.7 contain a heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler that can lead to a subscriber-wide denial of service. The flaw occurs before authentication, allowing a crafted NAS message to read arbitrary memory locations and consequently crash the AMF, disrupting mobile network services for all subscribers served by that AMF instance.
Affected Systems
The vulnerability affects the Open5GS open5gs project, specifically releases 2.7.7 and earlier. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1 % suggests that exploitation is currently rare and likely requires a highly targeted attack. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a remote adversary who can send crafted NAS messages to the AMF before authentication, triggering the out-of-bounds read that results in denial of service for all subscribers processed by that AMF instance.
OpenCVE Enrichment