Impact
The NGAP handler in free5gc v4.0.1 can be abused to cause a Denial of Service when an attacker sends a specially crafted NAS PDU. The flaw arises because the handler processes the PDU without proper validation or resource checks, leading to a crash or resource exhaustion that makes the control plane unavailable to legitimate users. The data does not indicate any impact on confidentiality or integrity beyond service interruption.
Affected Systems
free5gc v4.0.1; the vulnerability affects the NGAP handler module of this open‑source 5G core implementation.
Risk and Exploitability
The vulnerability can be triggered remotely, likely over the public or private export network via the NGAP interface, and does not require authentication. The CVSS score is 7.5, EPSS is not available. The described DoS nature and lack of mitigations suggest a high risk of exploitation in environments where the NGAP interface is exposed. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment