Impact
A flaw in the Open5GS NSSF component function ogs_sbi_stream_find_by_id within nghttp2-server.c causes the system to crash or hang when presented with a crafted input. The weakness, classified as CWE-404 (Missing Reference), creates a denial of service that stops the NSSF service from responding to normal traffic. The impact is a loss of availability for all users that depend on the NSSF function. The exploit requires locally‑executed manipulation, so an attacker must already have administrative or root access to the host to trigger the failure.
Affected Systems
Open5GS installations using version 2.7.7 or earlier are affected, as the vulnerability exists in the NSSF component of the platform. No additional sub‑product details are provided beyond the Open5GS project; all these versions across supported operating systems are potentially impacted when running the NSSF service.
Risk and Exploitability
The CVSS v3.1 score of 4.8 indicates a moderate severity. No EPSS score is published, so the likelihood of exploitation remains uncertain. The flaw is not listed in the CISA KEV catalog and demands local access, which reduces the appeal for external attackers. However, because the exploit is public and anyone with local privilege can trigger it, the risk for systems with compromised accounts or insecure local access is significant.
OpenCVE Enrichment