Impact
The vulnerability is an assertion failure in the CreateBearerRequest handler of Open5GS. When a specially crafted request is processed, the assertion is triggered, causing the system to terminate or become unstable. This can lead to a denial‑of‑service condition for the affected control plane instance, allowing a remote attacker to interrupt network service for connected users.
Affected Systems
Open5GS implementations up to and including version 2.7.6 are affected. The flaw resides in the sgwc_s5c_handle_create_bearer_request component, which processes CreateBearerRequest messages exchanged over the S5c interface.
Risk and Exploitability
The vulnerability carries a CVSS base score of 6.9 and an EPSS score below 1%, indicating a low but non‑zero likelihood of exploitation. Although it is not listed in CISA’s KEV catalogue, the issue has a publicly available exploit. The attack likely proceeds over the network by sending a malformed CreateBearerRequest to the Open5GS instance, exploiting the assertion to crash the process.
OpenCVE Enrichment