Impact
An attacker can trigger an assertion failure in the PFCP Session Report Request Handler of Open5GS, leading to an application crash and loss of availability. The flaw is caused by a manipulation of the request data that is not properly validated before the assertion is reached. Because the assertion is triggered during normal processing of a session report, a single crafted packet sent by an attacker can cause the SMF to terminate, denying service to all users currently served by that SMF instance.
Affected Systems
Open5GS implementations up to version 2.8.0 are affected. The issue resides in the function smf_n4_handle_session_report_request located in src/smf/n4-handler.c. No specific operating system or additional components are singled out; the vulnerability exists in the core Open5GS package as distributed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The flaw is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is remote: an attacker must be able to send PFCP packets to the N4 interface of an Open5GS SMF instance. If this interface is exposed to an untrusted network, the vulnerability could be abused to crash the SMF process, potentially disrupting services for all users attached to that SMF.
OpenCVE Enrichment