Impact
A bug in the AMF/MME component of Open5GS 2.7.7 and 2.8.0 allows an attacker to manipulate the code and obtain improper authorization. The flaw can be exploited remotely and has been publicly disclosed, meaning an attacker can potentially gain unauthorized access to core network functions used for mobile subscriber management.
Affected Systems
The vulnerability affects Open5GS deployments running version 2.7.7 or 2.8.0. It specifically targets the AMF/MME component responsible for authentication and mobility management.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is unavailable, and the vulnerability is not cataloged in CISA’s KEV list. Attackers can launch the exploit from a remote position, requiring only network access to the Open5GS instance. Once authorized, the attacker could bypass normal authorization checks and potentially execute further network-level attacks.
OpenCVE Enrichment