Exploit Database

149,665 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-14954 WRITEUP LOW
open5gs < 2.7.5 - Reachable Assertion in QER/FAR/URR/PDR Context Handling
A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_or_add/ogs_pfcp_qer_find_or_add in the library lib/pfcp/context.c of the component QER/FAR/URR/PDR. The manipulation leads to reachable assertion. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 442369dcd964f03d95429a6a01a57ed21f7779b7. Applying a patch is the recommended action to fix this issue.
CVSS 3.7
CVE-2025-14954 WRITEUP LOW
open5gs < 2.7.5 - Reachable Assertion in QER/FAR/URR/PDR Context Handling
A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_or_add/ogs_pfcp_qer_find_or_add in the library lib/pfcp/context.c of the component QER/FAR/URR/PDR. The manipulation leads to reachable assertion. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 442369dcd964f03d95429a6a01a57ed21f7779b7. Applying a patch is the recommended action to fix this issue.
CVSS 3.7
CVE-2025-14954 WRITEUP LOW
open5gs < 2.7.5 - Reachable Assertion in QER/FAR/URR/PDR Context Handling
A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_or_add/ogs_pfcp_qer_find_or_add in the library lib/pfcp/context.c of the component QER/FAR/URR/PDR. The manipulation leads to reachable assertion. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 442369dcd964f03d95429a6a01a57ed21f7779b7. Applying a patch is the recommended action to fix this issue.
CVSS 3.7
CVE-2025-14953 WRITEUP LOW
open5gs < 2.7.5 - Denial of Service via Null Pointer Dereference in FAR-ID Handler
A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component FAR-ID Handler. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is said to be difficult. The exploit has been published and may be used. This patch is called 93a9fd98a8baa94289be3b982028201de4534e32. It is advisable to implement a patch to correct this issue.
CVSS 3.1
CVE-2025-14953 WRITEUP LOW
open5gs < 2.7.5 - Denial of Service via Null Pointer Dereference in FAR-ID Handler
A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component FAR-ID Handler. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is said to be difficult. The exploit has been published and may be used. This patch is called 93a9fd98a8baa94289be3b982028201de4534e32. It is advisable to implement a patch to correct this issue.
CVSS 3.1
CVE-2025-14953 WRITEUP LOW
open5gs < 2.7.5 - Denial of Service via Null Pointer Dereference in FAR-ID Handler
A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component FAR-ID Handler. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is said to be difficult. The exploit has been published and may be used. This patch is called 93a9fd98a8baa94289be3b982028201de4534e32. It is advisable to implement a patch to correct this issue.
CVSS 3.1
CVE-2024-57519 WRITEUP HIGH
open5gs 2.7.2 - Denial of Service via ogs_dbi_auth_info Function
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.
CVSS 7.5
CVE-2024-56921 WRITEUP HIGH
open5gs - Denial of Service via gmm_state_exception() Error Handling
An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response.
CVSS 7.5
CVE-2024-40130 WRITEUP CRITICAL
open5gs v2.6.4 - Buffer Overflow in ABTS Core Library
open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.
CVSS 9.8
CVE-2024-40129 WRITEUP CRITICAL
Open5GS v2.6.4 - Heap-based Buffer Overflow in /lib/pfcp/context.c
Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.
CVSS 9.8
CVE-2024-34476 WRITEUP MEDIUM
open5gs < 2.7.1 - Denial of Service via NAS Message Handling in ogs_nas_encrypt
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
CVSS 5.3
CVE-2024-34476 WRITEUP MEDIUM
open5gs < 2.7.1 - Denial of Service via NAS Message Handling in ogs_nas_encrypt
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
CVSS 5.3
CVE-2024-34475 WRITEUP HIGH
open5gs < 2.7.1 - Denial of Service via NAS Message Handling in AMF
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.
CVSS 7.5
CVE-2024-34475 WRITEUP HIGH
open5gs < 2.7.1 - Denial of Service via NAS Message Handling in AMF
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.
CVSS 7.5
CVE-2024-33382 WRITEUP MEDIUM
Open5GS 2.7.0 - Denial of Service via Unsuccessful UE/gnb Registration
An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
CVSS 5.3
CVE-2023-50020 WRITEUP HIGH
open5gs v2.6.6 - Denial of Service via SIGPIPE
An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
CVSS 7.5
CVE-2023-50019 WRITEUP MEDIUM
open5gs v2.6.6 - Denial of Service via Nudm_UECM_Registration Response Error Handling
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
CVSS 5.9
CVE-2022-3354 WRITEUP LOW
open5gs < 2.4.10 - Denial of Service in UDP Packet Handler
A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic. This vulnerability affects unknown code in the library lib/core/ogs-tlv-msg.c of the component UDP Packet Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-209686 is the identifier assigned to this vulnerability.
CVSS 3.5
CVE-2022-3299 WRITEUP MEDIUM
Open5GS 2.4.0-2.4.10 - Denial of Service in AMF SBI Client
A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. The name of the patch is 724fa568435dae45ef0c3a48b2aabde052afae88. It is recommended to apply a patch to fix this issue. The identifier VDB-209545 was assigned to this vulnerability.
CVSS 4.3
CVE-2021-44109 WRITEUP HIGH
open5gs < 2.3.6 - Denial of Service via Crafted SBI Request
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.
CVSS 7.5
CVE-2021-44108 WRITEUP HIGH
Open5GS < 2.3.6 - Denial of Service via Crafted SBI Request to AMF
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.
CVSS 7.5
CVE-2021-44081 WRITEUP HIGH
open5gs 2.1.4 - Denial of Service via MSIN Length Overflow in AMF
A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.
CVSS 7.5
CVE-2021-28122 WRITEUP CRITICAL
Open5GS 2.1.3-2.2.0 - Unauthenticated Database Manipulation via WebUI API
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.
CVSS 9.8
CVE-2021-28122 WRITEUP CRITICAL
Open5GS 2.1.3-2.2.0 - Unauthenticated Database Manipulation via WebUI API
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.
CVSS 9.8
CVE-2021-28122 WRITEUP CRITICAL
Open5GS 2.1.3-2.2.0 - Unauthenticated Database Manipulation via WebUI API
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.
CVSS 9.8