Description
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
Published: 2026-08-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A reachable assertion in the NUDM‑UECM interface of Open5GS can be triggered by sending a crafted DELETE request, causing the gateway to crash or become unresponsive. This flaw does not expose confidential data or allow code execution; its sole impact is to disrupt the availability of the network function for legitimate users.

Affected Systems

The vulnerability is limited to the Open5GS NUDM‑UECM interface in version 2.7.6. It affects any installation that exposes this endpoint to external peers such as mobile device management components or other network functions.

Risk and Exploitability

The CVSS score of 7.5 indicates medium to high severity. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not yet in the CISA KEV catalog. The requirement to send a malicious DELETE request implies that an attacker must have network reachability to the Open5GS instance. When such reachability exists, exploitation would simply deny service to all users of that gateway.

Generated by OpenCVE AI on August 28, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch that addresses the CWE-617 Assertion Failure in the NUDM‑UECM interface.
  • Restrict access to the NUDM‑UECM endpoint so that only trusted internal networks or authenticated peers can reach it.
  • Limit or filter DELETE requests to the endpoint using firewalls, ACLs, or rate‑limiting mechanisms.

Generated by OpenCVE AI on August 28, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Assertion Failure in Open5GS NUDM-UECM Allows DoS via DELETE Request

Fri, 28 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Assertion Failure in Open5GS NUDM-UECM Allows DoS via DELETE Request

Fri, 28 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Reachable Assertion Vulnerability in Open5GS NUDM-UECM Leading to DoS
Weaknesses CWE-635

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Reachable Assertion Vulnerability in Open5GS NUDM-UECM Leading to DoS
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-617
CWE-635
Vendors & Products Open5gs
Open5gs open5gs
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T19:52:58.083Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-27T17:17:50.303

Modified: 2026-08-31T20:12:02.273

Link: CVE-2026-30046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T17:30:08Z

Weaknesses