Impact
The CreateUEContext handler in free5gc version 4.1.0 fails to validate a specially crafted request, allowing an attacker to trigger a denial of service. The flaw results in resource exhaustion that can make the network element unavailable for legitimate users, interrupting the service continuity of the 5G core.
Affected Systems
free5gc v4.1.0, the 5G core software component responsible for handling UE context creation, is the designated vulnerable version. No variant or vendor information is recorded beyond the free5gc project name.
Risk and Exploitability
Access to the vulnerability requires sending a crafted CreateUEContext request to the free5gc node over the network. The CVSS score of 7.5 describes the severity of the impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The lack of exploitation data suggests uncertainty about the prevalence of attacks, but the high CVSS score indicates a serious potential risk if the request is accepted.
OpenCVE Enrichment