Impact
A flaw exists in Open5GS versions up to 2.7.7 that corrupts the processing of data in the smf_nsmf_handle_created_data_in_vsmf function within the SMF component. The manipulation of this entry point can cause the service to crash, leading to a denial of service. The vulnerability is categorized as a CWE‑404 weakness, reflecting an error handling defect that allows an attacker to induce a failure state. Attackers can exploit the flaw remotely using a crafted payload published for public use.
Affected Systems
The affected vendor is Open5GS, with the product Open5GS. All releases from the initial release through 2.7.7 are vulnerable; later releases are presumed fixed but should be confirmed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be executed over the network without local access, and an exploit has been released in the wild. Because the flaw leads to a service crash, the impact is immediate loss of service for the affected SMF component and potentially any dependent functions that rely on it.
OpenCVE Enrichment