Impact
An attacker can cause a denial of service by sending a crafted HTTP request to the HTTPModifySubscription handler in free5gc version 4.0.1. The improper input validation allows the server to become unresponsive or crash, disrupting control plane services and potentially affecting all connected subscribers. The vulnerability does not compromise confidentiality or integrity, but loss of availability can have serious operational impact for mobile network operators.
Affected Systems
The vulnerability is present only in the free5gc implementation of 5G core network functions, specifically version 4.0.1. No other vendor or product is listed.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity, while the EPSS score is <1%, suggesting a very low probability of exploitation as of the current data. The weakness remains exploitable with any HTTP request to the affected endpoint and does not require authentication. The vulnerability is not listed in the CISA KEV catalog. Without an official patch, the risk remains unless mitigated by updating or hardening the service.
OpenCVE Enrichment