Impact
A NULL pointer dereference flaw exists in the AMF NGAP Dispatcher component of free5gc v4.0.1. When an adversary sends specially crafted NGAP messages during the setup of a new RAN connection, the dispatcher dereferences a null pointer, causing the process to crash. The resulting failure can render the entire AMF service unavailable, disrupting service for all connected RANs and users, thereby affecting availability rather than confidentiality or integrity.
Affected Systems
The vulnerability affects the free5gc project, specifically version 4.0.1 of the AMF NGAP Dispatcher. Any deployment of this open‑source 5G core that relies on this component is susceptible unless a patched or newer version is in use.
Risk and Exploitability
The CVSS score is 7.5, and the EPSS score is unavailable, but the denial‑of‑service impact is significant for operators relying on free5gc. The attack requires that a malicious or compromised RAN can send NGAP messages to the AMF; thus the vector is remote over the RAN–core interface. The vulnerability is not currently listed in CISA’s KEV catalog, which suggests limited reported exploitation but the potential impact remains high for vulnerable deployments.
OpenCVE Enrichment