Impact
An issue in the HandleGetSharedData function of free5gc v4.0.1 permits attackers to cause a denial of service by sending a specially crafted request. The flaw is a resource exhaustion vulnerability (CWE-770) that allows an attacker to create a state that overwhelms or blocks the application, rendering the service unavailable to legitimate users.
Affected Systems
The vulnerability is present only in free5gc version 4.0.1. Any deployment of the free5gc open‑source telecom software running that specific version is affected.
Risk and Exploitability
A crafted input can trigger the denial of service, but no code execution or privilege escalation is possible. The EPSS score of less than 1% combined with a CVSS score of 7.5 indicates a high severity but a relatively low probability of exploitation. The flaw is not listed in the CISA KEV catalog, so widespread weaponization is currently unlikely. However, the vulnerability can still cause significant operational disruption, especially in production networks where free5gc serves as the core mobility management element.
OpenCVE Enrichment