Impact
The vulnerability resides in the Open5GS AMF component, specifically within the amf_namf_comm_handle_registration_status_update_request function that handles the Transfer‑Update REST endpoint. By manipulating the ueContextId argument, an attacker can trigger an unhandled error that causes the application to crash and the AMF service to terminate. The attack results in a denial of service that affects all functions that depend on the AMF, potentially cascading to other network functions. The weakness corresponds to CWE‑404, a missing resource scenario.
Affected Systems
Open5GS, the open‑source 5G core network implementation, is affected in all releases through version 2.7.7.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. EPSS is not available and the vulnerability is not listed in CISA KEV. The exploit has already been published and can be initiated remotely via the HTTP REST interface. Because the exploit is publicly available, any deployed instance that exposes the Transfer‑Update API to untrusted networks remains at significant risk, especially in production environments.
OpenCVE Enrichment