github.com
https://github.com/free5gc/free5gc/issues/387 CVE-2022-38870
HIGHNuclei
Free5gc 3.2.1 - Information Disclosure
Record summary
CVE-2022-38870 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Free5gc v3.2.1 is vulnerable to Information disclosure.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 7, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryHIGHFree5gc 3.2.1 - Information DisclosureCVSS 7.5
Free5gc 3.2.1 is susceptible to information disclosure. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
Successful exploitation of this vulnerability could result in unauthorized access to sensitive information.
Remediation
Apply the latest patch or upgrade to a patched version of Free5gc 3.2.1 to mitigate the vulnerability.
WeaknessesCWE-306
AuthorsFor3stCo1d
Template tagscvecve2022free5gcexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:free5gc:free5gc:3.2.1:*:*:*:*:*:*:*
Shodan: http.title:"free5GC Web Console"
Shodan: http.title:"free5gc web console"
FOFA: title="free5gc web console"
Google: intitle:"free5gc web console"
https://github.com/free5gc/free5gc/issues/387 https://nvd.nist.gov/vuln/detail/CVE-2022-38870 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates https://github.com/Henry4E36/POCS
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-38870