Impact
An issue in the free5gc v4.1.0 ModifyAMFEventSubscriptionProcedure function enables an attacker to trigger a denial of service by sending a crafted PATCH request. The vulnerability stems from improper validation of the request payload, causing the server to consume excessive resources or crash. This flaw corresponds to CWE-770, which involves improper memory allocation leading to potential resource exhaustion.
Affected Systems
The affected system is the free5gc implementation, specifically version 4.1.0 of its AMF component. No other vendors or products are listed as affected.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not yet listed in CISA KEV, so there is no public evidence of exploitation. The CVSS score of 7.5 indicates a high severity DoS vulnerability. However, the attack likely originates from an external HTTP client that can issue PATCH requests to the AMF event subscription endpoint, a common entry point in 5G core networks. Because the flaw can be triggered by arbitrary client input, the risk of widespread denial of service exists if the affected software is deployed in production environments without mitigation.
OpenCVE Enrichment