Impact
The identified weakness resides in the HandleRegistrationComplete function within the AMF component of Free5GC version 4.1.0. A crafted request can trigger a denial of service, causing the AMF to stop responding to additional registration requests. This behavior is classified under CWE-404: Unhandled Resource Conflict. The vulnerability allows a remote attacker to disrupt service availability for the affected network functions.
Affected Systems
The CVE targets the Free5GC open‑source network function suite, specifically the AMF (Access and Mobility Management Function). The vulnerable code appears only in release 4.1.0. Systems running this exact version are at risk; later releases should be examined for the patch but are not explicitly listed as affected by this report.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity impact with remote exploitation potential. EPSS is not available, so the exploitation probability cannot be quantified. The vulnerability is not recorded in CISA’s KEV catalogue, implying no widespread public exploits are currently documented. Nevertheless, because the attack can be launched remotely and may cause service interruptions, administrators should consider the risk high enough to prioritize remediation.
OpenCVE Enrichment
Github GHSA