Impact
Key detail from CVE description: A vulnerability exists in Open5GS up to version 2.7.6 within the CCA Handler component (functions smf_gx_cca_cb, smf_gy_cca_cb, smf_s6b_aaa_cb, smf_s6b_sta_cb). The flaw allows remote manipulation that triggers a denial of service, potentially causing the SMF to crash or exhaust resources (Key detail from CVE description).
Affected Systems
Affected product: Open5GS from any release before 2.7.7. The risk applies to the smf_s6b_sta_cb handler path and associated functions listed in the CVE (Key detail from CVE description). No granular version matrix is provided, but all releases up to and including 2.7.6 are vulnerable. Version 2.7.7 or later contains the patch commit 80eb484a6ab32968e755e628b70d1a9c64f012ec, which resolves the issue (Reference: https://github.com/open5gs/open5gs/releases/tag/v2.7.7).
Risk and Exploitability
CVSS base score of 6.9 indicates a medium‑to‑high severity (Key detail from SCORES). EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The description notes the attack can be initiated remotely and the exploit is publicly disclosed, implying that attackers can use the flaw without privileged access (Key detail from CVE description). Consequently, the risk to impacted networks is significant and warrants prompt action.
OpenCVE Enrichment