Record summary

CVE-2022-38870 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Free5gc v3.2.1 is vulnerable to Information disclosure.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 7, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHFree5gc 3.2.1 - Information DisclosureCVSS 7.5

Free5gc 3.2.1 is susceptible to information disclosure. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Successful exploitation of this vulnerability could result in unauthorized access to sensitive information.

Remediation

Apply the latest patch or upgrade to a patched version of Free5gc 3.2.1 to mitigate the vulnerability.

WeaknessesCWE-306
AuthorsFor3stCo1d
Template tagscvecve2022free5gcexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:free5gc:free5gc:3.2.1:*:*:*:*:*:*:*
Shodan: http.title:"free5GC Web Console"
Shodan: http.title:"free5gc web console"
FOFA: title="free5gc web console"
Google: intitle:"free5gc web console"

Source: ProjectDiscovery

References

2