Impact
An integer overflow in the /nnrf-disc/v1/nf-instances component of Open5GS v2.7.6 can be triggered by sending a specially crafted HTTP/2 GET request, causing the server to crash and become unavailable. The flaw does not directly disclose sensitive data or allow code execution, but it disrupts network functionality for users relying on the affected component.
Affected Systems
This vulnerability affects the open-source Open5GS network function gateway, specifically version 2.7.6 of the NNRF instance discovery service exposed at the /nnrf-disc/v1/nf-instances endpoint. No other versions or vendor names have been reported as impacted.
Risk and Exploitability
The EPSS score is 0.00178, which is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Consequently, the risk from exploitation is low, but remote attackers who can reach the affected endpoint could still craft a malicious request to cause a service outage. With a CVSS score of 7.5, the severity is medium to high, highlighting the potential for widespread denial of service in deployments that rely on this component.
OpenCVE Enrichment