5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package open5gs-webui
- @LeSuisse dismissed
Open5GS context.c sgwc_bearer_add assertion
A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the file src/sgwc/context.c. The manipulation leads to reachable assertion. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The issue report is flagged as already-fixed.
References
-
-
-
Submit #729339 | Open5GS SGWC v2.7.6 Denial of Service third-party-advisory
-
https://github.com/open5gs/open5gs/issues/4233 issue-tracking
-
Affected products
- ==2.7.5
- ==2.7.1
- ==2.7.2
- ==2.7.4
- ==2.7.3
- ==2.7.0
Package maintainers
-
@Bot-wxt1221 Bot-wxt1221 <3264117476@qq.com>