Impact
A heap‑based buffer overflow exists in the Open5GS 2.8.0 component handling S6a Authentication‑Information‑Request messages. The flaw is triggered when the Visited‑PLMN‑Id argument supplied to the hss_ogs_diam_s6a_air_cb callback is manipulated, allowing an attacker to overflow a heap buffer. This can lead to arbitrary code execution or denial of service on the device that hosts the Open5GS HSS. The vulnerability is classified under CWE‑119 and CWE‑122, and its CVSS score of 5.3 indicates a moderate severity.
Affected Systems
The affected product is the Open5GS open source 5G core platform, specifically version 2.8.0. The flaw resides in the src/hss/hss‑s6a‑path.c file within the S6a Authentication‑Information‑Request handler. No other versions or vendors have been reported as impacted at this time.
Risk and Exploitability
The attack can be performed remotely by sending a specially crafted S6a Authentication‑Information‑Request to the HSS. Although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the CVSS score of 5.3 indicates a moderate risk for affected deployments. An attacker with network access to the S6a interface can potentially exploit the flaw to compromise the HSS or cause a denial of service.
OpenCVE Enrichment