Impact
A flaw has been identified in the Open5GS N1-N2 Message Handler that allows an attacker to manipulate the ngapIeType field within the N2InfoContent structure of an N1N2MessageTransfer request. By sending a crafted value, the software can experience a failure that results in a crash or unresponsive state, thereby denying service. The weakness is a type of improper input handling (CWE‑404).
Affected Systems
The vulnerability affects the Open5GS project, specifically versions up to and including 2.7.7. The issue is present in the amf_namf_comm_handle_n1_n2_message_transfer function inside src/amf/namf-handler.c, which processes N1‑N2 Message Transfers. All installations that have not upgraded beyond 2.7.7 and have enabled the N1‑N2 Message Handler component are potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. However, the exploit code has been publicly released and could be triggered remotely by an attacker with access to the N1‑N2 interface. The attacker can cause intermittent or permanent service outages, impacting availability for users relying on the 5G core network services.
OpenCVE Enrichment