Impact
The vulnerability resides in the CreateUEContextProcedure function that manages the /v1/ue‑contexts/{supi} REST endpoint in free5gc v4.1.0. A crafted PUT request can trigger the application to halt or become unresponsive, causing a denial of service to legitimate traffic. The weakness is a memory allocation failure triggered by the crafted request, which allows an attacker to exhaust or otherwise disrupt resources.
Affected Systems
free5gc v4.1.0. The product delivers core network functions for 5G networks and exposes the /v1/ue‑contexts endpoint for creating user equipment contexts. No other vendors or product variants are listed as affected.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score is < 1%, reflecting a low probability of exploitation in the wild. The vulnerability is not present in the CISA KEV catalog. The likely attack vector is remote network access to the REST endpoint, where an attacker sends crafted PUT requests to cause the service to stall. No official workaround is documented, so mitigation depends on operator action.
OpenCVE Enrichment