Impact
A reachable assertion in the SM‑Context endpoint of Open5GS causes the application to terminate when a specially crafted DELETE request is received. The failure of the assertion leads to a crash, denying service to all users of the affected 5G session management component.
Affected Systems
Open5GS version 2.7.6 exposes the vulnerable component at /nsmf-pdusession/v1/sm-contexts. No other versions are reported as affected, so the flaw is limited to this specific release.
Risk and Exploitability
The CVSS score is 7.5, and the EPSS score is unavailable. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network‑based via the HTTP API; an attacker who can reach the SM‑Context endpoint can trigger the flaw by sending a crafted DELETE command, resulting in a local denial of service to the targeted Open5GS deployment.
OpenCVE Enrichment