Impact
An issue in Free5GC version 4.2.2 allows a remote attacker to cause a denial of service through the UPF component. The flaw permits traffic that can trigger failures in the UPF, rendering the user plane component unresponsive and disrupting service.
Affected Systems
Free5GC version 4.2.2, specifically its User Plane Function (UPF) component. No other vendor or product variations are reported.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high-severity vulnerability, and the EPSS score of less than 1% suggests a low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Because the vulnerability is remote, an attacker with network access to the UPF can potentially disrupt the user plane traffic of the affected Free5GC deployment.
OpenCVE Enrichment