Impact
Free5GC versions up to 4.1.0 contain a null pointer dereference in the establishPfcpSession function of the SMF component. When this function receives a crafted request, it dereferences a null pointer, causing the SMF process to crash. This vulnerability leads to a denial‑of‑service condition and may allow an attacker to disrupt 5G core network services. The weakness corresponds to CWE‑404 (Improper Resource Shutdown or Release) and CWE‑476 (NULL Pointer Dereference).
Affected Systems
The affected product is Free5GC, the open‑source 5G core implementation. All releases up through version 4.1.0 are impacted; later releases contain the patched code.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate to high severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is remote, and the exploit is publicly disclosed. An attacker can trigger the crash by sending a specially crafted SMF request over the network. As the flaw is not authenticated, any host able to reach the SMF control plane is a potential target.
OpenCVE Enrichment