Impact
A flaw in Open5GS 2.8.0, within the AMF UEContextReleaseRequest Path Handler, can lead to improper authorization when a request is manipulated. This issue aligns with CWE‑266 and CWE‑285, indicating weaknesses in authorization logic that allow an attacker to bypass legitimate controls. By exploiting this flaw, an attacker could potentially gain unauthorized access to control‑plane operations for a user equipment, enabling further malicious actions.
Affected Systems
The affected product is the Open5GS open‑source 5G core network, specifically version 2.8.0. No other versions or vendor variations are listed in the available data. The flaw lies in the AMF component’s UEContextReleaseRequest Path Handler.
Risk and Exploitability
The CVSS base score of 5.3 designates a moderate level of risk, while no EPSS score is available, so the exploitation probability cannot be quantified. It is not listed in the CISA KEV catalog, indicating no known active exploitation. The attack vector is remote; the description states that manipulation can be executed over the network, and the vulnerability originates from improper authorization checks, implying that an attacker could forge or alter a UEContextReleaseRequest to obtain unauthorized privileges. No higher‑level impact such as denial of service or code execution is reported in the advisory.
OpenCVE Enrichment