Impact
Free5GC, a 5G core network implementation, contains a flaw in the PFCP UDP Endpoint component. The flaw, classified as CWE‑404, results in a denial of service when the affected function processes crafted data. An attacker who can reach the endpoint remotely can trigger the failure, causing service interruption for the affected PFCP interface.
Affected Systems
Any installation of Free5GC version 4.1.0 or earlier is susceptible. The vulnerability arises from an unspecified function within the PFCP UDP Endpoint module. Users running these versions should assess whether the PFCP service is exposed to external networks.
Risk and Exploitability
With a CVSS score of 6.9 the issue is considered medium severity, and the EPSS score of less than 1 % indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, but an exploit has been publicly disclosed and may be used. The attack vector is remote, owing to the use of UDP, and would require the attacker to send a specially crafted packet to the vulnerable endpoint.
OpenCVE Enrichment