Impact
The vulnerability stems from improper validation of inputs in the buildFilter function within free5gc v4.0.1. Based on the description, the attack vector is inferred to involve sending a malicious request to the buildFilter function. An attacker can craft a malicious request that triggers the function to consume excessive resources, eventually resulting in a service crash. This flaw directly impacts the availability of the free5gc core network, potentially exposing the system to repeated outages without altering confidentiality or integrity.
Affected Systems
The affected product is the free5gc open‑source 5G core stack, specifically version 4.0.1. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires sending a specially crafted request to the buildFilter endpoint, exploitation confidence is uncertain and would depend on the attacker’s ability to reach the target. The CVSS score of 7.5 reflects a high severity denial of service impact, meaning successful exploitation would cause the free5gc core network to become unavailable. No public exploitation evidence is currently known.
OpenCVE Enrichment