Impact
A flaw in the Open5GS PFCP Message Handler, specifically in lib/pfcp/handler.c, allows a remote attacker to cause a denial of service by sending a carefully crafted PFCP message. The vulnerability triggers a resource exhaustion or crash in the server component, interrupting service availability. The weakness is classified as CWE-404.
Affected Systems
The vulnerability affects the Open5GS platform, versions up to and including 2.7.7. All stack that have not applied the fix identified by commit 028e1dbb5e3271035ccee906ef417a97fc523f71 are potentially exposed.
Risk and Exploitability
With a CVSS score of 6.9 and an EPSS score of less than 1%, the vulnerability presents a moderate risk. Public exploits have been released, and remote exploitation is possible. An attacker can manipulate network traffic to a PFCP endpoint, triggering a denial of service and potentially disrupting 5G network operations.
OpenCVE Enrichment