Impact
The vulnerability resides in the OpenAPI_list_create function of the Open5GS SMF component. Manipulation of this endpoint can cause the service to become unavailable, resulting in a denial of service that affects all users relying on the affected SMF instance. The weakness is classified as CWE-404, indicating a defect related to resource access or missing validation, and the CVSS score of 5.3 reflects a moderate severity of the impact.
Affected Systems
This flaw touches Open5GS products through version 2.7.7 inclusive. The SMF (Serving Gateway) portion of the Open5GS suite is implicated, and any deployment using these versions is susceptible. No more granular version information is available beyond the upper bound of 2.7.7. Managers of Open5GS installations should verify that their instances fall within this range.
Risk and Exploitability
The attack appears to be launched remotely, as the public exploit details reference remote manipulation of the API endpoint. However, the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed mass exploitation yet. The publicly disclosed nature of the exploit adds a risk that attackers may discover and utilize the flaw before an official fix is delivered, especially if the SMF endpoint is exposed to the internet. Overall, the moderate CVSS score and lack of mitigation from the maintainers suggest that the vulnerability poses a tangible threat to the availability of the affected service.
OpenCVE Enrichment