Impact
A null pointer dereference occurs in the ogs_pfcp_parse_volume_measurement function within the PFCP Handler of Open5GS. When malformed PFCP messages are processed, the code attempts to dereference a null pointer, causing the PFCP service to crash or become unresponsive. The resulting denial of service can disrupt mobile network control plane operations. This weakness is consistent with CWE-476 and CWE-404, indicating uninitialized or null pointer dereferencing.
Affected Systems
Open5GS, the open-source 5G core network stack, is affected through all releases up to and including version 2.8.0. Operators running these firmware layers are at risk if they have not applied the upstream patch that fixes the issue.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate to high impact when exploited. With an EPSS score of less than 1 %, the likelihood of a widespread, automated exploitation campaign is currently low. However, because the attack can be launched remotely and does not require privileged access, it remains a viable target for adversaries with network reach to the PFCP endpoint. The vulnerability is not listed in the CISA KEV catalog as of this analysis, so no known active exploits have been reported, but the patch is strongly recommended.
OpenCVE Enrichment