Impact
An issue in the NAS decoder component of free5gc v4.0.1 allows an attacker to craft a malformed Registration Request message that, when processed, can cause a denial of service condition. The flaw may involve improper input validation and uncontrolled resource consumption. An additional pointer or bounds error (CWE-770) may also contribute to the failure of the decoder to recover, potentially corrupting the decoder’s internal state and terminating the process. The vulnerability’s primary impact is the loss of service availability. Since the description states a DoS can be caused, a crash or the inability to process further requests is a plausible consequence, though the exact behavior is not explicitly detailed.
Affected Systems
The vulnerability is confined to the NAS decoder module of the free5gc open‑source 5G core network stack, specifically version 4.0.1. No other vendor–specific products or earlier more recent releases are mentioned.
Risk and Exploitability
The EPSS score is reported as < 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that active exploitation has not been observed. However, the CVSS score of 7.5 denotes a high severity level. The most likely attack vector is remote, inferred from the fact that the vulnerable component processes Registration Requests received over the user network. Because the flaw can be triggered without local access or user interaction, an adversary could induce service disruption from a remote location. The combination of high severity and low current exploitation probability suggests that the risk is moderate but could increase if the vulnerability becomes publicly exploited.
OpenCVE Enrichment