Impact
A bug in Open5GS HSS component hss-cx-path.c allows a remote attacker to send a specially crafted User-Name string that triggers an assertion failure. The resulting assertion failure can crash the HSS service, causing a denial of service and potentially exposing sensitive state before termination. This flaw is identified as a reachable assertion (CWE-617).
Affected Systems
All Open5GS deployments running versions up to and including 2.8.0 are vulnerable. The flaw resides in the HSS component, which is used by the core network to handle subscriber information. Any instance that processes external HSS CX requests is at risk.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity; no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Exploit code has been published and the attack can be performed remotely over the control plane network. The lack of an EPSS value does not diminish the risk of denial of service if the flaw remains unpatched, especially in exposed or multi-tenant deployments.
OpenCVE Enrichment