Impact
The issue resides in the RechargePut function of free5gc v4.0.1, where an attacker can send a specially crafted input that triggers the service to consume excessive resources and become unresponsive. This lack of input validation leads to an uncontrolled resource consumption weakness that results in a denial of service.
Affected Systems
The vulnerability affects the free5gc networking platform, specifically the 4.0.1 release. Other releases that contain the same code path for RechargePut may also be vulnerable, but only the 4.0.1 version is explicitly mentioned.
Risk and Exploitability
The EPSS score indicates a low (less than 1%) probability of exploitation. The issue is not listed in the CISA KEV catalog. The CVSS score is 7.5, indicating high severity. The severity of the risk depends on the environment; an attacker capable of targeting the RechargePut function could potentially cause the node to stop responding to requests. Because the description does not indicate any authentication requirement, the DoS may be possible to trigger from external traffic, giving it a medium to high likelihood of exploitation in exposed deployments.
OpenCVE Enrichment