Impact
A flaw in the NRF component of Open5GS, affecting the function ogs_sbi_nf_instance_set_id in /lib/sbi/context.c, allows an attacker to manipulate the nfInstanceId argument, resulting in a denial of service. The weakness is classified as CWE-404. An affected system could become unavailable to legitimate users when the flaw is triggered, disrupting services that depend on the NRF for network function registration and discovery.
Affected Systems
The vulnerability impacts Open5GS deployments up to version 2.7.6. All supported releases up to that point are potentially affected unless a later version addresses the issue. Vendors and system administrators should verify the exact version in use.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity for denial of service. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is described as remote, meaning the exploitation can occur over a network connection. An exploit has been published, which may be used by threat actors to disrupt service availability. Because no official patch or workaround has yet been released, the risk remains unless mitigated through other controls.
OpenCVE Enrichment