Impact
A flaw exists in the NGSetupRequest handler in Free5GC version 4.2.0 that allows an attacker to manipulate the request so that the component crashes or becomes unresponsive, resulting in a denial of service. This disrupts critical 5G core network functions and can affect carrier operations. The issue stems from a logical error that was identified as CWE-404.
Affected Systems
Free5GC is an open‑source 5G core network implementation. The vulnerability specifically affects version 4.2.0 and any builds derived from that code base. No other product versions or vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. Exploitation is possible remotely and the exploit code is publicly available, according to the description. No EPSS score is reported, and the vulnerability is not yet in the CISA KEV catalog, but the potential for widespread denial of service remains a concern for operators relying on the affected Free5GC release.
OpenCVE Enrichment