Impact
A null pointer dereference in the Transfer Endpoint component of Open5GS's AMF (namf-handler.c) can be triggered remotely, potentially causing the application to crash and leading to a denial of service. This vulnerability corresponds to CWE-476 and CWE-404, indicating an uninitialized object use and a missing resource scenario.
Affected Systems
The vulnerability affects Open5GS deployments up to version 2.7.7. Upgrading to version 2.8.0 or later incorporates the patch commit abf8a836564b966b5141110fc25ed413c4f17522, which resolves the issue.
Risk and Exploitability
With a CVSS score of 5.3, the severity is moderate. No EPSS data is available, and the vulnerability is not listed in CISA KEV, suggesting a relatively low exploitation probability. However, the remote attack vector noted in the description means an attacker with network access to the AMF could trigger a crash, impacting availability for connected users.
OpenCVE Enrichment