Impact
In Open5GS versions up to 2.7.x the function amf_nnrf_try_old_amf_discovery_fallback in nnrf-handler.c contains a use‑after‑free flaw triggered by manipulation of the discovery_option argument. An attacker who can send a crafted request to the AMF service can cause memory corruption that may lead to a denial of service or, depending on the system state, arbitrary code execution.
Affected Systems
Installations of Open5GS 2.7.x and prior where the Old AMF Discovery Fallback component is enabled. The vulnerability exists in the core AMF server code and does not affect other components.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS score is not available, and the vulnerability is not listed in CISA KEV catalog, so community‑reported exploitation likelihood is uncertain. The flaw is remotely exploitable through normal service traffic, requiring network access to the AMF service and the ability to craft a specific discovery_option payload to trigger the use‑after‑free.
OpenCVE Enrichment