Impact
A reachable assertion in the NUDM‑UECM interface of Open5GS can be triggered by sending a crafted DELETE request, causing the gateway to crash or become unresponsive. This flaw does not expose confidential data or allow code execution; its sole impact is to disrupt the availability of the network function for legitimate users.
Affected Systems
The vulnerability is limited to the Open5GS NUDM‑UECM interface in version 2.7.6. It affects any installation that exposes this endpoint to external peers such as mobile device management components or other network functions.
Risk and Exploitability
The CVSS score of 7.5 indicates medium to high severity. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not yet in the CISA KEV catalog. The requirement to send a malicious DELETE request implies that an attacker must have network reachability to the Open5GS instance. When such reachability exists, exploitation would simply deny service to all users of that gateway.
OpenCVE Enrichment